Privacy Notice
This notice explains how personal data is processed when you use our website or contact us. We use Cookiebot consent management to ensure compliance with data protection regulations.
Controller
Jhonathan Campos
Trading as Oversight - Governance Studio
Berlin, Germany
Email: jhonathanaugusto@gmail.com
Until incorporation of a separate legal entity, the controller is the natural person above operating under the trade name "Oversight - Governance Studio".
What data we collect
We only process personal data that you actively provide via the contact form or email:
- Your name
- Your email address
- The content of your message
Cookie management and analytics
We use Cookiebot (by Usercentrics A/S, Denmark) as a consent management platform to control cookies and trackers on our website in compliance with GDPR requirements.
Analytics Services
With your consent, we use Google Analytics and Google Tag Manager through Google Consent Mode integration. These services only process data when you explicitly consent to statistics and marketing cookies.
Consent Management
Your consent preferences are stored securely for as long as we rely on your consent for processing. You can change or withdraw your consent at any time using the cookie settings.
Purposes and legal bases
Contact Data Processing
We process your data solely to respond to your enquiry and manage related correspondence. Legal basis: Art. 6(1)(b) GDPR (steps prior to a contract) or Art. 6(1)(f) GDPR (legitimate interest).
Analytics Data Processing
When you consent, we process data to understand website performance and user behavior. Legal basis: Art. 6(1)(a) GDPR (consent). Without consent, only anonymous aggregate data is processed under Art. 6(1)(f) GDPR (legitimate interest).
Service providers (processors)
We use the following service providers under GDPR-compliant data processing terms:
Cookiebot by Usercentrics A/S (Denmark)
Consent management platform that scans, controls cookies, and stores consent preferences (data stored in EU).
Vercel Inc.
Website hosting and delivery (technical operation).
Brevo (Sendinblue SAS)
SMTP relay for contact form submissions (email delivery platform based in Paris, France).
Google Ireland Limited / Google LLC
Analytics and Tag Manager services (only when you consent to statistics/marketing cookies; operates through Google Consent Mode).
International Transfers: Where data is transferred to the United States (e.g., Google LLC, Vercel), transfers rely on the EU–US Data Privacy Framework and/or the European Commission's Standard Contractual Clauses, as applicable.
Storage duration
Contact Enquiries
We retain contact data only as long as necessary to process your request and to comply with statutory retention duties (e.g., German commercial and tax law).
Consent Records
Stored for as long as we rely on your consent for processing, to demonstrate compliance with data protection regulations.
Your rights
You have the rights of access, rectification, erasure, restriction, portability, and objection (Arts. 15–21 GDPR). You can change your cookie consent at any time. You also have the right to lodge a complaint with a supervisory authority.
Competent authority in Berlin: Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59–61, 10555 Berlin — datenschutz-berlin.de
Security
We use TLS/SSL encryption for transport and secure email transmission via Brevo SMTP. Cookiebot processes consent data in secure EU-based data centers. Access to all systems is restricted to authorized personnel only.
Changes to this notice
We may update this notice to reflect changes in our processing. The latest version is always available on this page.
Last updated: 30 September 2025