Privacy contact
For requests concerning data processed directly by this website, use the contact email below. Requests will be reviewed under applicable Brazilian data-protection rules and the relevant relationship with the data subject.
This page explains how this website handles personal data and which external services may receive technical data while you browse.
Updated October 2026For requests concerning data processed directly by this website, use the contact email below. Requests will be reviewed under applicable Brazilian data-protection rules and the relevant relationship with the data subject.
During public browsing, hosting infrastructure and security mechanisms may record technical data required to operate and protect the service, such as IP address, date and time, browser user agent and requested resource. This website has no local reservation form: bookings are redirected to the official external booking engine.
The CMS is restricted. For administrators, the system stores a user identifier, passwords only as hashes and security audit records. Audit records include IP address, action and date/time and are technically retained for up to 90 days by the application.
The delivered website code does not use advertising or behavioural profiling cookies. A strictly necessary session cookie is created only when the restricted CMS area is opened. Google Fonts are loaded to preserve the visual identity. Google Maps loads automatically in the website location area and may receive technical connection data during loading. Links to the booking engine, WhatsApp, Instagram and Facebook open third-party services governed by their own policies.
Technical data is processed to provide the website, maintain security, prevent abuse and record administrative events. Booking and contact operations occur in the relevant external services. The applicable legal basis depends on the specific operation and may include contract performance, compliance with legal or regulatory obligations and legitimate interests where applicable and subject to data-subject rights.
Technical data may be processed by the hosting infrastructure and, when a visitor activates external features, by the relevant providers. Some services may operate infrastructure outside Brazil.
Under the LGPD, data subjects may request, as applicable, confirmation of processing, access, correction, anonymisation, blocking or deletion of unnecessary or unlawfully processed data, information about sharing, portability where applicable, withdrawal of consent and objection in cases provided by law.
The application includes access controls, session protection, CSRF protection, login rate limiting, upload validation, parameterised queries, security headers, audit logging and a retention policy for administrative logs. No system can eliminate all risk; incidents must be assessed and handled under applicable law.