Cookie Policy — EvoCODE IA®
Last updated: September 30, 2026 · Version 2.0
This Cookie Policy explains how EvoCODE IA® Ltda ("EvoCODE", "we", "us") uses cookies and similar technologies in the Kairo (kairo.evocode.ia.br), TraceLog (tracelog · evocode.ia.br), and AgenteNOC (agentenoc.evocode.ia.br and panel) products, as well as on the corporate website https://evocode.ia.br. It forms part of our legal hub and must be read together with the Privacy Policy. In the event of a conflict, the order of precedence declared in the hub prevails: DPA > Terms of Service > AUP > documentation.
This policy was drafted in compliance with the LGPD (Lei Geral de Proteção de Dados — Brazilian General Data Protection Law, Law No. 13,709/2018), the ANPD's Guidance on cookies and personal data protection and, where applicable to visitors from other regions, with the European ePrivacy regime and the GDPR.
1. What cookies and similar technologies are
Cookies are small text files that a website stores in your browser or device. They can be read by the same website on subsequent visits and are used, for example, to keep you authenticated, remember preferences, or measure audience.
We also use similar technologies, which we treat in this policy in the same way as cookies:
- localStorage / sessionStorage: browser storage areas used to store interface preferences (theme, language, sidebar state) and the record of your cookie consent. Unlike cookies, this data is not automatically sent to the server with each request.
- Pixels and tags: small elements or scripts loaded from our own or third-party servers that allow events to be measured (e.g., tags managed via Google Tag Manager, when enabled).
- Embedded third-party resources: fonts, players, and widgets loaded from external servers (e.g., Google Fonts, VdoCipher player), which may expose your IP address to the third party and, in some cases, set their own cookies.
As to origin, cookies may be first-party (set by our own domains) or third-party (set by external domains). As to duration, they may be session cookies (which expire when the browser is closed) or persistent cookies (which remain for a defined period).
2. Cookie categories and legal bases
Following the classification recommended by the ANPD's guidance, we organize cookies and similar technologies into four categories, each with its own legal basis:
| Category | What it does | Legal basis (LGPD) | Can it be disabled? |
|---|---|---|---|
| Necessary | Authentication and session, security (CSRF, anti-bot), load balancing, recording of the consent itself, essential operation of features you request (e.g., booking in an iframe) | Performance of a contract (Art. 7, V) and legitimate interest (Art. 7, IX) — security and operation of the service | No. Without them the service does not work; for this reason they do not depend on consent |
| Preferences (functional) | Remembering language, light/dark theme, interface state | Legitimate interest (Art. 7, IX), with minimal impact on the data subject; can be disabled in the preferences panel | Yes |
| Analytics (statistical) | Measuring usage and performance to improve the product | Legitimate interest with a documented Legitimate Interest Assessment (LIA) in the case of first-party, aggregated measurement; consent (Art. 7, I) where third parties or individualized profiles are involved — as is the case with Google Tag Manager in TraceLog | Yes |
| Marketing (advertising) | Advertising, remarketing, campaign measurement | Consent (Art. 7, I), always. Never activated without your affirmative choice | Yes |
For visitors from the European Economic Area, the United Kingdom, and Québec, all non-strictly-necessary cookies depend on prior consent (opt-in), pursuant to Article 5(3) of the ePrivacy Directive and local legislation.
Important: we do not sell or share personal data for cross-context behavioral advertising, within the meaning of US state laws.
3. Cookies used, by product
The tables below reflect an actual technical audit of our systems as of the date of this version. If a cookie or technology ceases to be listed here or is added, we will update this policy and the version indicated at the top.
3.1 Kairo (kairo.evocode.ia.br)
| Name | Type | Purpose | Duration | Category |
|---|---|---|---|---|
kairo_session |
cookie | Session/authentication | 120 min | Necessary |
XSRF-TOKEN |
cookie | CSRF protection | Session | Necessary |
remember_web_* |
cookie | "Remember me" feature | ~5 years | Necessary (set only if you use "remember me") |
evocode_embed |
cookie | Booking context in embedded iframe | Session | Necessary (functional to the booking routes) |
sidebar:state |
JS cookie | Sidebar UI preference | 7 days | Preferences |
sidebar, appearance, i18nextLng |
localStorage | UI state, theme, language | Persistent | Preferences |
| Google Fonts | third party | Loading of the Outfit font (exposes your IP address to Google) | — | Third party |
Kairo does not currently use analytics or marketing cookies.
3.2 TraceLog
| Name | Type | Purpose | Duration | Category |
|---|---|---|---|---|
tracelog_session |
cookie | Session/authentication | 120 min | Necessary |
XSRF-TOKEN |
cookie | CSRF protection | Session | Necessary |
remember_web_* |
cookie | "Remember me" feature | ~5 years | Necessary |
Cloudflare Turnstile (cf_*) |
third party | Anti-bot verification at login | — | Necessary (security) |
| Google Tag Manager | conditional third party | Analytics/marketing (only if gtm_id is active in the installation) |
— | Analytics/Marketing — CONSENT required |
tracelog_cookie_consent, i18nextLng |
localStorage | Record of cookie consent; language | Persistent | Necessary / Preferences |
| Google Fonts | third party | Loading of the Outfit font | — | Third party |
Note on Google Tag Manager: the GTM script is not loaded before your consent. It is only injected into the page after you accept the Analytics and/or Marketing categories in the banner or in the preferences panel. If you reject or withdraw consent, the script ceases to be loaded on subsequent navigation.
3.3 AgenteNOC (application and panel)
| Name | Type | Purpose | Duration | Category |
|---|---|---|---|---|
Session cookie (evocode-ia-painel-agente-noc-session in the panel; its own name in the app) |
cookie | Session/authentication | 120 min | Necessary |
XSRF-TOKEN |
cookie | CSRF protection | Session | Necessary |
remember_web_* |
cookie | "Remember me" feature | ~5 years | Necessary |
Cloudflare Turnstile (cf_*) |
third party | Anti-bot verification on the authentication forms (login, registration, password reset) | — | Necessary (security) |
| VdoCipher | third party (iframe) | DRM player for course videos in the panel | — | Necessary (feature you requested) |
| Google Tag Manager | conditional third party | Usage measurement and analytics (only if gtm_id is configured in the panel Settings) — loads the Google Analytics _ga/_ga_*/_gid cookie family |
Per Google: _ga/_ga_<container-id> up to 2 years, _gid up to 24h (duration set by the loaded tags, outside our direct control) |
Analytics/Marketing — CONSENT required |
theme/sidebar (Filament) |
localStorage | Interface preferences | Persistent | Preferences |
agentenoc_voice_push_to_talk, agentenoc_voice_mic_threshold_* |
localStorage | Voice-call microphone settings (push to talk and per-agent sensitivity), stored only when you change them | Persistent | Preferences |
agentenoc_partner_ref |
localStorage | Attributes the sign-up to the referring partner/reseller (code captured from the ?parceiro= link) |
60 days | Marketing — requires CONSENT |
The VdoCipher player is only loaded on course pages containing video; when you access them, your browser communicates with VdoCipher's servers. We classify VdoCipher as Necessary because you are the one requesting the content by opening the lesson — the player is the very feature requested, under the same logic as the other necessary items in Section 2 — not because a specific consent gate exists before it loads.
Note on Google Tag Manager: when a gtm_id is configured, the GTM script (gtm.js) is only loaded after you grant valid consent for Analytics and/or Marketing in the banner or the preferences panel — it is not injected into the page by default, nor before your decision. Under the Global Privacy Control signal (Section 4.4), the script is never loaded, even if a consent was previously saved. As an additional layer of protection, in the absence of valid consent — and always under the Global Privacy Control signal — Consent Mode v2 sets the measurement signals to denied before any loading; so, even in the event of a failure of the check above while no valid consent exists, measurement cookies and signals (_ga, _ga_*, _gid, and related) would remain blocked. Rejecting or withdrawing consent stops the script from loading on subsequent navigation.
3.4 Third parties and international transfers
The third-party resources identified above (Google Fonts in Kairo and TraceLog, Google Tag Manager, Cloudflare Turnstile, VdoCipher) may entail the communication of your IP address and technical metadata to providers located outside Brazil. In AgenteNOC, the interface fonts (Inter and Outfit) are self-hosted — no request is made to Google's servers to load them, so no IP address is exposed through this channel. These transfers comply with Resolution CD/ANPD No. 19/2024 and the mechanisms described in the international transfers section of our Privacy Policy. The complete list of subprocessors for each product is published in the legal hub.
4. How to manage cookies
4.1 Consent banner (two levels)
On your first visit to each product, we display a two-layer banner:
- Level 1 — summary: a brief explanation and three buttons of equal prominence: Accept all, Reject non-essential, and Preferences. No optional category is pre-checked.
- Level 2 — granular: per-category control — Necessary (always active), Preferences, Analytics, and Marketing — with a description of each.
Until you make a choice, no non-essential script is loaded.
4.2 Preferences panel
You may review and change your choices at any time via the "Cookie/privacy preferences" link in the footer of each product. Withdrawing consent is as simple as granting it.
4.3 Browser settings
All modern browsers allow you to block or delete cookies and clear localStorage (usually under Settings → Privacy). Note: blocking necessary cookies prevents login and use of the products.
4.4 Global Privacy Control (GPC)
We honor the Global Privacy Control signal. From the moment your browser or extension sends it:
- the Analytics and Marketing categories are automatically and immediately refused — no script in these categories is loaded, regardless of whether you interact with the banner or already have a previously saved decision;
- in the banner and the preferences panel, the Analytics and Marketing controls appear locked (they cannot be turned on while the signal is present), and the primary button changes to "Accept allowed", granting only Necessary and Preferences;
- if you interact with the banner or the panel while the signal is active, we record the decision (Section 5) with its origin identified as GPC, for audit purposes.
Where required by applicable law, this is equivalent to an opt-out of the "sale/sharing" of data — the refusal of Analytics and Marketing takes effect without any additional action on your part beyond the browser signal itself.
To reverse this refusal, disable Global Privacy Control in your browser or the extension that sends it, and redo your choice in the banner or the preferences panel.
5. How we record and withdraw consent
When you interact with the banner or the preferences panel, we record, in your own browser (e.g., the agentenoc_cookie_consent key in AgenteNOC; tracelog_cookie_consent in TraceLog):
- the choice per category (accepted/refused);
- the date and time of the choice;
- the version of this policy in force at the time.
Consent validity: this choice is valid for up to 12 months from the date of the record. Once it expires — or if we publish a new version of this policy — we treat the previous consent as non-existent and the banner is shown again automatically on your next visit, without requiring any action on your part beyond continuing to use the product.
Record in our systems (authenticated users): when you are authenticated, in addition to the record in your browser, we also keep a history of your decisions in our systems, containing only: the chosen category (Preferences, Analytics, Marketing), the policy version in force at the time of the decision, the date and time of the decision, and the origin of the record (first banner, reopened panel, or Global Privacy Control signal). For data minimization purposes, we do not collect your IP address or browser information (user-agent) in this history — the data subject is already identified by their account.
This record allows us to prove consent (Art. 8, paragraph 2, LGPD) and to respect your choice on subsequent visits. When you withdraw consent:
- the scripts of the withdrawn categories immediately cease to be loaded on subsequent navigation;
- cookies already set by those scripts expire naturally or may be removed by the browser — we explain how to do so in Section 4.3;
- we record the withdrawal with date, time, and version, in the same manner as the acceptance (Art. 8, paragraph 5, LGPD).
Retention of the history: the consent history kept in our systems is tied to your account and is retained for as long as the account exists. If you delete your account, this history is deleted along with it — we do not retain proof of consent for closed accounts.
If we publish a material change to this policy or add new non-essential purposes, the banner will also be shown again for a new choice.
6. Updates and contact
We may update this Cookie Policy to reflect technical, legal, or product changes. The version and date at the top always indicate the edition in force; material changes will be communicated by notice in the product.
Questions about cookies and privacy, or data subject requests (Art. 18 of the LGPD), may be directed to our Data Protection Officer (DPO), Elizandro Pacheco de Almeida, at dpo@evocode.ia.br. Note: where the data is processed by us in the capacity of processor on behalf of a customer (tenant), we may redirect your request to the responsible controller, providing due assistance.
EvoCODE IA® Ltda · CNPJ 63.623.332/0001-42 Praça Nossa Senhora do Rosário, 44, Sala 02 — Centro, Piracaia/SP — CEP 12970-000 — Brasil, Brazil Website: https://evocode.ia.br · E-mail: contato@evocode.ia.br · Support: sac@evocode.ia.br · Official WhatsApp: +55 51 2191-0021 (https://wa.me/555121910021) Data Protection Officer (DPO): Elizandro Pacheco de Almeida — dpo@evocode.ia.br