Privacy Policy

PRIVACY POLICY 

Last Updated: August 28, 2026 

2EB is operated by TIHEE LTD, BC Number: TIHEE LTD 2178872, with its registered office at Level 1, Palm Grove House, Wickham’s Cay 1, Road Town, Tortola, British Virgin Islands (hereinafter referred to as  “2EB,” “we,” “us,” or “our”). 

Advertising intermediation and monetization for the website are provided by TiMo Midia Ltda., registered  under CNPJ No. 62.179.475/0001-44, with its registered office at Rua Ana de Carvalho Silveira, No. 287, Apt.  302, Silveira, Belo Horizonte/MG, ZIP Code 31.140-440 (“TiMo Mídia”), which is responsible for the  intermediation and monetization of the programmatic advertising inventory displayed on the website. 

This Privacy Policy describes how we collect, use, share, and protect the personal data of our visitors and  readers, in compliance with Brazil’s General Data Protection Law (LGPD, Law No. 13,709/2018), the Brazilian  Internet Civil Framework (Law No. 12,965/2014), the Consumer Protection Code (Law No. 8,078/1990), and,  where applicable, the data protection laws of other countries to which we direct Content, as detailed in the Local Addendum at the end of this document. By accessing or using the website, you acknowledge that you have read, understood, and agree to this document. 

1. SCOPE OF THE POLICY 

This Policy applies to the processing of personal data in connection with this website and the technologies used  on it and, where applicable, to digital properties and advertising inventories operated or monetized by TiMo  Mídia in connection with the website. It covers activities such as security, measurement, fraud and invalid traffic prevention, performance improvement, advertising delivery and verification, and user support. 

This Policy does not apply to third-party websites, products, or services, even when accessed through links or  advertisements displayed here, nor to environments that expressly identify another company as the primary  controller. 

Where a Local Addendum applies to your country or relevant jurisdiction, that Addendum supplements this  Policy. In the event of a conflict, the Local Addendum prevails only to the extent necessary to comply with  mandatory local law. 

2. NATURE OF THE OPERATION (ADTECH) 

TiMo Mídia operates as an AdTech company specializing in technical infrastructure, digital advertising  inventory management, optimization, and monetization of advertising spaces for publishers and media outlets.  Its activities include programmatic advertising, audience measurement, prevention of traffic fraud, bots, and  technical abuse, as well as email marketing and newsletter solutions for retaining its own audience. 

3. PRIVACY PRINCIPLES 

We maintain technical and administrative controls based on the following principles: Transparency: providing clear information about the purposes of data processing. 

Purpose limitation: processing data only for legitimate and disclosed purposes. 

Data minimization: collecting data that is necessary and proportionate to the operation. Security and prevention: adopting reasonable measures to protect data and mitigate incident risks. Accountability: being accountable for implementing effective compliance measures. 

Respect for user choices: ensuring practical mechanisms for managing consent and opt-out where applicable. Limited retention: retaining data only for as long as necessary for legitimate purposes.

4. IMPORTANT DEFINITIONS 

Personal Data: information that identifies or makes an individual identifiable, including online identifiers. 

Technical Data: records generated by devices during access, such as logs, network metadata, and software  characteristics. 

Aggregated or Anonymized Data: information subjected to processes that prevent reasonable association with an individual. 

Cookies: small files stored in a browser to record preferences and technical parameters. Pixels, Tags, and Web Beacons: elements used to monitor events, such as ad delivery or email opens. Programmatic Advertising: automated buying and selling of advertising space. 

Online Identifiers: technical codes, such as cookie IDs or advertising IDs, associated with browsers or devices. 

Invalid Traffic (IVT): impressions, clicks, or events generated artificially or by bots that distort actual metrics,  including incentivized or deceptive clicks. 

Controller: the party that determines the main purposes and means of processing. 

Operator/Processor: the party that processes data on behalf of and under the instructions of the Controller. 

Independent Controller: a third party that determines its own processing purposes when interacting with the  ecosystem. 

5. ROLES AND ALLOCATION OF RESPONSIBILITIES 

5.1 Our Role 

We are responsible for the editorial operation of this website, published Content, the domain, hosting (except  where contracted with TiMo Mídia), our own forms, the products and services described, and responding to  requests related to such Content. 

5.2 Role of TiMo Mídia 

Depending on the technical context of the operation, TiMo Mídia may act: 

As a Controller, when it determines the purposes and means of processing, such as in managing the security of  its own campaigns and protecting its infrastructure; 

As an Operator/Processor, when it provides technology or processes data on our behalf and according to our  instructions; 

As a technical monetization partner, operating infrastructure that connects the website to advertising demand  networks; 

Alongside Independent Controllers, such as Google, SSPs, DSPs, ad exchanges, ad servers, and anti-fraud and  measurement tools, which may process data under their own policies, legal bases, and responsibilities. 

5.3 Allocation of Responsibilities 

TiMo Mídia is not automatically responsible for the editorial content, hosting, domain, legal notices, our own  forms, commercial support, products, services, or commercial promises of this website when those activities  remain under our control. We are not automatically responsible for the advertising technology layer,  programmatic integrations, advertising consent signals, fraud prevention, or invalid-traffic prevention when  those activities remain under TiMo Mídia’s technical control. 

The exact legal qualification of each party will depend on the purposes of processing, the means actually  determined by each participant, the technical configuration of the environment, and the mandatory rules of the  applicable jurisdiction. Where necessary, specific agreements may be entered into between us and TiMo Mídia  to establish roles, responsibilities, joint processing, and cooperation with competent authorities.

6. DATA WE COLLECT 

6.1 Technical and Browsing Data 

IP address and approximate geographic location derived from the IP address; 

Date and time of access, pages accessed, referring and exit URLs; 

Browser, operating system, device type, language, screen resolution, and user agent; 

Cookie and advertising identifiers; 

Logs, click events, impressions, interactions with advertisements, security signals, and traffic patterns. 6.2 Cookie and Consent Data 

Recorded preferences, consents granted, denied, or revoked; 

Date, time, and version of consent; 

Opt-out options and recognized privacy preference signals, where required and technically supported. 6.3 Advertising and Monetization Data 

Ad requests and frequency, viewability and brand-safety metrics; 

Inventory information, aggregated reports, and aggregated performance and revenue data; Anti-fraud signals and traffic-audit data; 

Device identifiers, audience segments, and ad preferences managed by the advertising platforms used on the  website. 

6.4 Voluntarily Provided Data 

Name, email address, telephone number, and company, when provided in forms, quizzes, or contact messages; Content of messages, documents, or attachments submitted through support channels; Data necessary to validate data-subject requests. 

6.5 Push Notification and Email Marketing Data 

Device token and notification preferences, collected solely with prior express consent when the website offers  this feature; 

Email address, name (when provided), registration source, and subscription date and time; 

Proof of opt-in, communication preferences, and sending, delivery, open, click, rejection, and spam-complaint  history; 

Unsubscribe records and data maintained on suppression lists. 

6.6 Sensitive Data and Minors 

We do not seek to collect sensitive data or children’s data. Our digital environments are not directed to  individuals under 18. If inadvertent collection of minors’ data without an appropriate legal basis is identified, we will take reasonable measures to delete, anonymize, or restrict processing. 

7. PURPOSES OF PROCESSING 

We process collected data for: technical operation, stability, and performance of the website; security, fraud  prevention, combating bots, abusive scraping, and invalid traffic (IVT); audience measurement and performance analysis; advertising monetization, delivery, measurement, frequency management, and optimization; contextual advertising and maintenance of brand safety; personalized advertising where there is a valid legal basis; consent  management and reporting; user support and defense of rights in proceedings or audits; compliance with legal  obligations; sending newsletters and email communications; and management of unsubscribes and suppression  lists.

8. LEGAL BASES FOR PROCESSING 

Consent (LGPD Article 7(I)): for non-essential cookies, push notifications, personalized behavioral advertising,  and audience matching data sharing (Section 13.2). Consent may be withdrawn at any time (LGPD Article 15)  through the channels identified in Section 25. 

Legitimate Interest (LGPD Article 7(IX)): for technical operation, security, fraud prevention, contextual  advertising, and aggregated metrics, while respecting your rights. 

Performance of a contract or preliminary procedures (LGPD Article 7(V)): for responding to requests. 

Compliance with a legal or regulatory obligation (LGPD Article 7(II)): for retention of logs and compliance  with judicial and regulatory orders. 

Exercise of legal rights (LGPD Article 7(VI)): for our and TiMo Mídia’s legal protection. 

9. COOKIES AND SIMILAR TECHNOLOGIES 

The operation may involve cookies, pixels, tags, local storage, and session identifiers, organized as follows: 

Necessary: essential for stability, security, and consent management—they do not depend on consent because  they are indispensable to the website’s operation; 

Functional: save basic choices, such as language and region; 

Measurement: collect technical traffic data on an aggregated basis; 

Advertising: used for ad delivery, frequency capping, ecosystem protection, and targeted advertising; Security: focused on preventing anomalous activity and fraud. 

Preference management may be performed through the banner or preference center, when available, or through  browser settings. Disabling cookies may affect website functionality. For third-party advertising cookies, you  may also visit optout.aboutads.info. 

10. PROGRAMMATIC ADVERTISING AND RELATIONSHIP WITH GOOGLE AND PARTNERS 

TiMo Mídia uses advertising technology platforms, including Google Ad Manager, Google Ad Exchange  (AdX), Google AdSense, and MCM, and may operate as a partner within the Google ecosystem, as applicable.  These partners may process technical data, online identifiers, and browsing information to select advertisements, measure performance, prevent fraud, limit frequency, protect advertisers, generate reports, and comply with  their platform policies. 

We and TiMo Mídia undertake to operate in compliance with Google Ad Manager/AdSense/AdX program  policies, including the prohibition of invalid traffic, incentivized clicks, deceptive content, and manipulation of  ad units (e.g., ad stacking, pixel stuffing). Failure by any party to comply with these rules may place the  advertising account of the entire network at risk. 

You can personalize the ads you see on Google services and control the information used to personalize them at  myadcenter.google.com/home. For more information about how Google processes data on partner websites, see  policies.google.com/technologies/partner-sites. 

11. CONSENT MODE AND MANAGEMENT OF TECHNICAL SIGNALS 

Where applicable, we integrate Google Consent Mode, which governs technical signals such as ad_storage,  analytics_storage, ad_user_data, and ad_personalization according to your choice. 

If you deny or withdraw consent, tags operate with restrictions: systems may send signals without cookies,  perform aggregated data modeling, or stop using information for personalized advertising.

12. EMAIL MARKETING, NEWSLETTERS, AND ELECTRONIC  COMMUNICATIONS 

When we offer newsletters or email communications, sending is based on an appropriate legal basis—consent or legitimate interest, depending on the jurisdiction. 

Right to unsubscribe: every email contains a clear and functional opt-out mechanism, honored within the  applicable legal timeframe. 

Tracking: where permitted, emails may contain pixels, web beacons, or tracking links to measure delivery,  opens, clicks, and engagement. 

Suppression list: after unsubscribing, the address is retained on a suppression list for as long as necessary to  prevent improper new sends, demonstrate compliance with the request, and protect the operation against  improper re-importation. 

Complaints about unsolicited communications may be sent through the channels identified in Section 25. 

13. DATA SHARING 

13.1 Categories of Recipients 

We may share data, to the extent necessary, with: hosting, CDN, and infrastructure providers; cybersecurity and  fraud-prevention services; analytics and measurement tools (e.g., Google Analytics); CMP and tag-management  providers; programmatic advertising platforms, SSPs, DSPs, ad exchanges, and ad servers; email marketing and  push-notification providers, when used; consultants and auditors, with safeguards; other digital properties  

operated by us or by the same network, solely to recommend relevant products and services; and public  authorities pursuant to a legal obligation, court order, or valid request. 

We do not sell your personal data to third parties. Each partner operates under its own privacy policy and is  individually responsible for the processing it performs. 

13.2 Audience Matching and Conversion Measurement 

When you complete a form or quiz and confirm your email address through explicit consent, we may share with  partner advertising platforms (e.g., Google Ads, through Customer Match and Enhanced Conversions, and Meta, through the Conversions API) encrypted versions—one-way, non-reversible SHA-256 hashes—of your email  address and name, together with campaign and browser identifiers when available (e.g., gclid, fbclid). The  purposes are conversion measurement and attribution, creation of custom audiences, and creation of suppression audiences to exclude individuals who have opted out. 

We do not send email addresses, names, telephone numbers, addresses, or any other personal data in readable or reversible form to these platforms—only the hash, which cannot be reversed to recover the original data. The  legal basis is free, informed, and unambiguous consent (LGPD Article 7(I)), collected at the time of completion  through an unchecked consent box, and revocable at any time through the channels in Section 25. 

Hashes remain in partner-platform audiences for the period defined by their respective policies (currently up to  540 days for Google Customer Match, renewable upon each interaction) or until consent is withdrawn,  whichever occurs first. 

14. INTERNATIONAL DATA TRANSFERS 

Due to the international nature of the internet, cloud computing, and programmatic advertising, data may be  processed and stored outside your country of residence—including by providers based in the United States, such as Google. We adopt safeguards for these transfers, including standard contractual clauses approved by the  Brazilian data protection authority (ANPD) under Article 33 of the LGPD, and other mechanisms recognized by applicable law. 

15. DATA RETENTION AND DISPOSAL 

We retain data for as long as necessary for the purposes of this Policy, including compliance with legal  obligations, consent records, defense of rights, administration of suppression lists, technical and anti-fraud logs,  aggregated reports, and email-marketing data while there is a legal basis, an active relationship, or a legitimate 

need. Browsing data and access logs are retained for at least six months, as required by Article 15 of the  Brazilian Internet Civil Framework, and may be retained longer when necessary for the purposes of this Policy  or pursuant to a legal requirement. Once no longer necessary, data is securely deleted or anonymized. 

16. DATA SUBJECT RIGHTS 

You may exercise, at any time, the following rights: confirmation of the existence of processing; access to your  data; correction of incomplete, inaccurate, or outdated data; anonymization, blocking, or deletion of unnecessary 

data or data processed in violation of law; portability to another provider, where technically feasible; deletion of  data processed based on consent; information about sharing with third parties; withdrawal of consent; objection  to processing; and review of automated decisions, where applicable. 

To exercise these rights regarding editorial content and the website’s own functionalities, contact us through the  website channel identified in Section 25. To exercise these rights specifically regarding the programmatic  advertising layer operated by TiMo Mídia—including data processed under Section 13.2—contact  [email protected]. 

We may request additional information to verify your identity. We will respond within 15 days, pursuant to  Article 18(3) of the LGPD; deadlines under other jurisdictions are set out in the applicable Local Addendum. 

You also have the right to file a complaint with Brazil’s National Data Protection Authority (ANPD) if you  believe your rights as a data subject have been violated: gov.br/anpd, Esplanada dos Ministérios, Bloco C, 4th  floor, Brasília/DF, ZIP Code 70.297-400. 

17. OPT-OUT, DO NOT SELL OR SHARE, AND PRIVACY PREFERENCE  SIGNALS 

Where applicable law recognizes a right to opt out of “sale,” “sharing,” or behavioral/personalized/targeted  advertising, we will provide appropriate mechanisms through the preference center, contact channel, or  recognition of signals such as Global Privacy Control, where technically supported. After opting out of  personalized advertising, you may continue to see contextual advertisements that are not targeted through  profiling. 

18. INFORMATION SECURITY 

We adopt technical and organizational measures appropriate to the risks, including HTTPS connections,  encryption in transit, least-privilege access controls, audit logs, firewalls, monitoring, bot prevention, and anti fraud tools, seeking alignment with international standards such as ISO/IEC 27001 and 27701. No system  connected to the internet is completely immune to risks, external infrastructure failures, or incidents caused by  third parties. 

19. SECURITY INCIDENT RESPONSE PLAN 

In the event of a confirmed or suspected security incident under our responsibility, we will act to identify,  contain, and investigate the threat and adopt mitigation measures. Notification to authorities and data subjects  will occur when required by law—in Brazil, pursuant to Article 48 of the LGPD—while maintaining internal  documentation of the measures taken. 

20. AUTOMATED DECISIONS AND PROFILING 

Automated processing of signals occurs primarily for security, detection of invalid traffic, bot prevention,  measurement, and advertising segmentation. We do not seek to make solely automated decisions that produce  significant legal effects or similarly significant impacts on you without a legal basis, transparency, and respect  for applicable rights. 

21. LINKS, ADVERTISEMENTS, AND THIRD PARTIES 

The website may display third-party advertisements, scripts, integrations, or links. We do not fully control these  external environments, which have their own privacy policies and data practices. Clicking an advertisement and 

visiting a partner’s page does not create a relationship with us—we recommend reviewing each third-party  website’s privacy policy before providing information. 

22. DIGITAL ACCESSIBILITY 

We make reasonable efforts to align the development of our interfaces with digital inclusion and web  accessibility principles (WCAG 2.2 AA), where technically feasible. Technical barriers may be reported through the channels identified in Section 25. 

23. LANGUAGES AND VERSIONS 

This Policy may be made available in other languages. In the event of an interpretive discrepancy, the official  Brazilian Portuguese version prevails, except where mandatory local law requires otherwise in the User’s  jurisdiction of residence. 

24. UPDATES TO THIS POLICY 

This Policy may be revised at any time. The “Last Updated” date at the beginning indicates the current version.  Material changes will be communicated through a visible notice on the website when required by law. 

LOCAL ADDENDUM TO THE PRIVACY POLICY 

Where applicable, processing will comply with U.S. federal and state privacy laws, including the CCPA/CPRA  where applicable, as well as the CAN-SPAM Act for commercial communications. 

Where the sharing of identifiers with programmatic advertising partners is characterized under applicable law as a sale, sharing, or targeted/behavioral advertising activity, the User may exercise an opt-out right. 

Where required by applicable law and technically supported by the relevant digital environment, privacy  preference signals such as Global Privacy Control (GPC) will be treated as an opt-out request. Commercial  emails will include appropriate identification and a functional unsubscribe mechanism. 

25. CONTACT 

TIHEE LTD: [email protected] 

TiMo Mídia (Compliance/DPO): [email protected]