Cookie Policy — EvoCODE IA®

Last updated: September 1, 2026 · Version 2.1

This Cookie Policy explains how EvoCODE IA® Ltda ("EvoCODE", "we", "us") uses cookies and similar technologies in the Kairo (kairo.evocode.ia.br), TraceLog (tracelog · evocode.ia.br), and AgenteNOC (agentenoc.evocode.ia.br and panel) products, as well as on the corporate website https://evocode.ia.br. It forms part of our legal hub and must be read together with the Privacy Policy. In the event of a conflict, the order of precedence declared in the hub prevails: DPA > Terms of Service > AUP > documentation.

This policy was drafted in compliance with the LGPD (Lei Geral de Proteção de Dados — Brazilian General Data Protection Law, Law No. 13,709/2018), the ANPD's Guidance on cookies and personal data protection and, where applicable to visitors from other regions, with the European ePrivacy regime and the GDPR.


1. What cookies and similar technologies are

Cookies are small text files that a website stores in your browser or device. They can be read by the same website on subsequent visits and are used, for example, to keep you authenticated, remember preferences, or measure audience.

We also use similar technologies, which we treat in this policy in the same way as cookies:

  • localStorage / sessionStorage: browser storage areas used to store interface preferences (theme, language, sidebar state) and the record of your cookie consent. Unlike cookies, this data is not automatically sent to the server with each request.
  • Pixels and tags: small elements or scripts loaded from our own or third-party servers that allow events to be measured (e.g., tags managed via Google Tag Manager, when enabled).
  • Embedded third-party resources: fonts, players, and widgets loaded from external servers (e.g., Google Fonts, VdoCipher player), which may expose your IP address to the third party and, in some cases, set their own cookies.

As to origin, cookies may be first-party (set by our own domains) or third-party (set by external domains). As to duration, they may be session cookies (which expire when the browser is closed) or persistent cookies (which remain for a defined period).

Following the classification recommended by the ANPD's guidance, we organize cookies and similar technologies into four categories, each with its own legal basis:

Category What it does Legal basis (LGPD) Can it be disabled?
Necessary Authentication and session, security (CSRF, anti-bot), load balancing, recording of the consent itself, essential operation of features you request (e.g., booking in an iframe) Performance of a contract (Art. 7, V) and legitimate interest (Art. 7, IX) — security and operation of the service No. Without them the service does not work; for this reason they do not depend on consent
Preferences (functional) Remembering language, light/dark theme, interface state Legitimate interest (Art. 7, IX), with minimal impact on the data subject; can be disabled in the preferences panel Yes
Analytics (statistical) Measuring usage and performance to improve the product Legitimate interest with a documented Legitimate Interest Assessment (LIA) in the case of first-party, aggregated measurement; consent (Art. 7, I) where third parties or individualized profiles are involved — as is the case with Google Tag Manager in TraceLog Yes
Marketing (advertising) Advertising, remarketing, campaign measurement Consent (Art. 7, I), always. Never activated without your affirmative choice Yes

For visitors from the European Economic Area, the United Kingdom, and Québec, all non-strictly-necessary cookies depend on prior consent (opt-in), pursuant to Article 5(3) of the ePrivacy Directive and local legislation.

Important: we do not sell or share personal data for cross-context behavioral advertising, within the meaning of US state laws.

3. Cookies used, by product

The tables below reflect an actual technical audit of our systems as of the date of this version. If a cookie or technology ceases to be listed here or is added, we will update this policy and the version indicated at the top.

3.1 Kairo (kairo.evocode.ia.br)

Name Type Purpose Duration Category
kairo_session cookie Session/authentication 120 min Necessary
XSRF-TOKEN cookie CSRF protection Session Necessary
remember_web_* cookie "Remember me" feature ~5 years Necessary (set only if you use "remember me")
evocode_embed cookie Booking context in embedded iframe Session Necessary (functional to the booking routes)
sidebar:state JS cookie Sidebar UI preference 7 days Preferences
sidebar, appearance, i18nextLng localStorage UI state, theme, language Persistent Preferences
Google Fonts third party Loading of the Outfit font (exposes your IP address to Google) Third party

Kairo does not currently use analytics or marketing cookies.

3.2 TraceLog

Name Type Purpose Duration Category
tracelog_session cookie Session/authentication 120 min Necessary
XSRF-TOKEN cookie CSRF protection Session Necessary
remember_web_* cookie "Remember me" feature ~5 years Necessary
Cloudflare Turnstile (cf_*) third party Anti-bot verification at login Necessary (security)
Google Tag Manager conditional third party Analytics/marketing (only if gtm_id is active in the installation) Analytics/Marketing — CONSENT required
tracelog_cookie_consent, i18nextLng localStorage Record of cookie consent; language Persistent Necessary / Preferences
Google Fonts third party Loading of the Outfit font Third party

Note on Google Tag Manager: the GTM script is not loaded before your consent. It is only injected into the page after you accept the Analytics and/or Marketing categories in the banner or in the preferences panel. If you reject or withdraw consent, the script ceases to be loaded on subsequent navigation.

3.3 AgenteNOC (application and panel)

Name Type Purpose Duration Category
Session cookie (evocode-ia-painel-agente-noc-session in the panel; its own name in the app) cookie Session/authentication 120 min Necessary
XSRF-TOKEN cookie CSRF protection Session Necessary
remember_web_* cookie "Remember me" feature ~5 years Necessary
VdoCipher third party (iframe) DRM player for course videos in the panel Functional (third party)
theme/sidebar (Filament) localStorage Interface preferences Persistent Preferences

The VdoCipher player is only loaded on course pages containing video; when you access them, your browser communicates with VdoCipher's servers.

3.4 Third parties and international transfers

The third-party resources identified above (Google Fonts, Google Tag Manager, Cloudflare Turnstile, VdoCipher) may entail the communication of your IP address and technical metadata to providers located outside Brazil. These transfers comply with Resolution CD/ANPD No. 19/2024 and the mechanisms described in the international transfers section of our Privacy Policy. The complete list of subprocessors for each product is published in the legal hub.

4. How to manage cookies

On your first visit to each product, we display a two-layer banner:

  • Level 1 — summary: a brief explanation and three buttons of equal prominence: Accept all, Reject non-essential, and Preferences. No optional category is pre-checked.
  • Level 2 — granular: per-category control — Necessary (always active), Preferences, Analytics, and Marketing — with a description of each.

Until you make a choice, no non-essential script is loaded.

4.2 Preferences panel

You may review and change your choices at any time via the "Cookie/privacy preferences" link in the footer of each product. Withdrawing consent is as simple as granting it.

4.3 Browser settings

All modern browsers allow you to block or delete cookies and clear localStorage (usually under Settings → Privacy). Note: blocking necessary cookies prevents login and use of the products.

4.4 Global Privacy Control (GPC)

We honor the Global Privacy Control signal. If your browser or extension sends the GPC signal, it will be treated as a valid refusal of the Analytics and Marketing categories (and, where required by applicable law, as an opt-out of the "sale/sharing" of data), without any additional action on your part.

When you interact with the banner or the preferences panel, we record, in your own browser (e.g., the tracelog_cookie_consent key in TraceLog) and, when you are authenticated, in our systems:

  • the choice per category (accepted/refused);
  • the date and time of the choice;
  • the version of this policy in force at the time.

This record allows us to prove consent (Art. 8, paragraph 2, LGPD) and to respect your choice on subsequent visits. When you withdraw consent:

  • the scripts of the withdrawn categories immediately cease to be loaded on subsequent navigation;
  • cookies already set by those scripts expire naturally or may be removed by the browser — we indicate in the panel how to do so;
  • we record the withdrawal with date, time, and version, in the same manner as the acceptance.

If we publish a material change to this policy or add new non-essential purposes, the banner will be shown again for a new choice.

6. Updates and contact

We may update this Cookie Policy to reflect technical, legal, or product changes. The version and date at the top always indicate the edition in force; material changes will be communicated by notice in the product.

Questions about cookies and privacy, or data subject requests (Art. 18 of the LGPD), may be directed to our Data Protection Officer (DPO), Elizandro Pacheco de Almeida, at dpo@evocode.ia.br. Note: where the data is processed by us in the capacity of processor on behalf of a customer (tenant), we may redirect your request to the responsible controller, providing due assistance.


EvoCODE IA® Ltda · CNPJ 63.623.332/0001-42 Praça Nossa Senhora do Rosário, 44, Sala 02 — Centro, Piracaia/SP — CEP 12970-000 — Brasil, Brazil Website: https://evocode.ia.br · E-mail: contato@evocode.ia.br · Support: sac@evocode.ia.br · Official WhatsApp: +55 51 2191-0021 (https://wa.me/555121910021) Data Protection Officer (DPO): Elizandro Pacheco de Almeida — dpo@evocode.ia.br