Legal

Privacy Policy

Last updated: March 4, 2026 · Effective immediately

1 Introduction

KATIANNA LARISSA DE CARVALHO LOPES FERREIRA LTDA ("Katianna," "we," "us," or "our"), registered under CNPJ 48.314.062/0001-02, is committed to protecting the privacy and security of your personal information. This Privacy Policy explains how we collect, use, store, share, and protect your data when you interact with our website, store, services, and communications.

We comply with the Brazilian General Data Protection Law (Lei Geral de Proteção de Dados — LGPD, Law No. 13,709/2018), the Brazilian Consumer Defense Code (CDC), and are committed to international best practices in data privacy and information security.

2 Data Controller

Company: KATIANNA LARISSA DE CARVALHO LOPES FERREIRA LTDA
CNPJ: 48.314.062/0001-02
Address: R. 15 de Novembro, 10, Q 2 LT 32, Santana, Goiás – GO, 76600-000, Brasil
Contact: contact@katiannajewelry.com.br

3 Data We Collect

We may collect the following categories of personal data depending on how you interact with us:

CategoryExamplesPurpose
Identity DataFull name, date of birth, CPFPurchases, invoicing, custom orders
Contact DataEmail, phone, addressCommunication, delivery, support
Financial DataPayment method, transaction historyPayment processing, invoicing
Technical DataIP address, browser, device infoSecurity, website analytics
Purchase DataItems purchased, preferences, wish listsService, recommendations
Custom Order DataDesign specifications, measurementsBespoke jewelry creation

High-Value Transaction Data: As a jewelry retailer, certain purchases may require additional identity verification to comply with Brazilian anti-money laundering regulations. This data is collected solely for legal compliance and is treated with the highest level of security.

4 How We Use Data

We process your personal data for the following purposes:

Sales & Service: To process purchases, manage custom orders, arrange delivery or pickup, issue invoices, handle returns and warranty claims, and provide after-sales services such as cleaning, repair, and appraisal.

Communication: To send order confirmations, appointment reminders, care instructions, and with your consent, promotional offers, new collection announcements, and event invitations.

Personalization: To provide tailored product recommendations and private viewing invitations based on your purchase history and preferences.

Legal Compliance: To comply with tax, invoicing, consumer protection, and anti-money laundering regulations applicable to jewelry retail in Brazil.

Security: To protect our physical and digital assets, prevent fraud, and ensure the safety of high-value transactions.

5 Legal Basis

In accordance with Article 7 of the LGPD, we process your data under the following legal bases:

Consent: For marketing communications, personalized recommendations, and event invitations.

Contract Performance: For processing purchases, custom orders, repairs, and warranty claims.

Legal Obligation: For invoice issuance, tax compliance, and anti-money laundering requirements.

Legitimate Interest: For fraud prevention, security monitoring, service improvement, and basic analytics, provided these do not override your fundamental rights.

6 Data Sharing

We do not sell, rent, or trade your personal information. We may share data only under these circumstances:

Payment Processors: Secure payment gateways that process your financial transactions in compliance with PCI-DSS standards.

Delivery Partners: Specialized insured courier services for high-value items, receiving only the information necessary for secure delivery.

Service Providers: Trusted third parties who assist with website hosting, analytics, email services, and CRM systems, bound by contractual data protection obligations.

Legal Authorities: When required by law, court order, or governmental authority, including tax and anti-money laundering reporting obligations.

All third-party providers are carefully vetted and contractually required to maintain appropriate security measures in compliance with applicable data protection regulations.

7 Data Retention

We retain your personal data only for as long as necessary to fulfill its purpose or as required by law. Active customer data is retained throughout your relationship with us plus 5 years. Transaction and invoice records are retained as required by Brazilian tax law (minimum 5 years). Custom order specifications are retained for the duration of any applicable warranty. Marketing consent data is kept until you withdraw consent. Appraisal and certification records are retained for 10 years.

8 Your Rights Under LGPD

Under the LGPD, you have the following rights regarding your personal data:

Confirmation & Access: Confirm whether we process your data and access a copy of it.

Correction: Request correction of incomplete, inaccurate, or outdated data.

Anonymization, Blocking, or Deletion: Request anonymization, blocking, or deletion of unnecessary or excessive data.

Data Portability: Request transfer of your data to another provider in a structured format.

Consent Withdrawal: Withdraw consent at any time, without affecting prior processing. This includes unsubscribing from marketing communications.

Objection: Object to processing based on legitimate interest if you believe your rights are being violated.

To exercise these rights, contact us at contact@katiannajewelry.com.br. We will respond within 15 business days.

9 Cookies

Our website may use cookies and similar technologies to enhance your experience:

Essential Cookies: Required for core website functionality and security. Cannot be disabled.

Analytics Cookies: Help us understand how visitors interact with our site to improve navigation and content.

Preference Cookies: Remember your settings, such as wish list items and recently viewed products.

Marketing Cookies: Used to deliver relevant promotions and new collection announcements, activated only with your consent.

You can manage cookie preferences through your browser settings at any time.

10 Data Security

We implement robust security measures to protect your personal data, including SSL/TLS encryption for all website transactions, PCI-DSS compliant payment processing, access controls with role-based permissions, regular security audits and vulnerability assessments, employee training on data protection and confidentiality, documented incident response procedures, and physical security measures at our retail location.

Given the high-value nature of our products, we apply enhanced security protocols for transaction records and customer profiles. Financial data is processed exclusively by PCI-DSS certified payment partners and is never stored on our servers.

11 International Transfers

If your data is transferred outside of Brazil (for example, through cloud hosting or analytics services), we ensure appropriate safeguards are in place in accordance with Chapter V of the LGPD, including standard contractual clauses, adequacy decisions by the ANPD, or your explicit consent.

12 Children's Privacy

Our services are directed at adults and are not intended for individuals under the age of 18. We do not knowingly collect personal data from minors. Purchases made on behalf of minors (such as gifts) are processed using the adult purchaser's data only. If we become aware that a minor has provided personal data, we will take immediate steps to delete it.

13 Policy Changes

We may update this Privacy Policy periodically to reflect changes in our practices, technologies, or legal requirements. Significant changes will be communicated through our website, email, or in-store notices. We encourage you to review this page regularly to stay informed about how we protect your data.

14 Contact Us

For questions, concerns, or data rights requests:

KATIANNA LARISSA DE CARVALHO LOPES FERREIRA LTDA
R. 15 de Novembro, 10, Q 2 LT 32
Santana, Goiás – GO, 76600-000, Brasil
Email: contact@katiannajewelry.com.br
CNPJ: 48.314.062/0001-02

You also have the right to file a complaint with the Brazilian National Data Protection Authority (ANPD — Autoridade Nacional de Proteção de Dados) if you believe your data protection rights have been violated.