Privacy Policy

Last updated: 8 September 2026.

This policy explains how TCC Tools ("we", "the site") collects, uses and protects information about its visitors. It is written to comply with the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA/CPRA) and the Brazilian General Data Protection Law (LGPD, Law No. 13,709/2018).

Data controller

[FULL NAME OR REGISTERED COMPANY NAME]
[CITY], Mato Grosso, Brazil
Contact: contact page

We are established outside the European Economic Area. We have not appointed an EU representative under Article 27 GDPR, as our processing of EEA residents' data is occasional, limited to anonymous analytics and advertising cookies, and does not involve special categories of data.

1. Your research data is processed locally

This is the most important point in this policy: every file you load (.xlsx, .csv spreadsheets, PDFs) and every statistical computation runs exclusively inside your own browser, through JavaScript executing on your device. No file, dataset, result or generated text is ever transmitted to, stored on, copied by or analysed on our servers. When you close or reload the tab, that data is gone completely. We have no technical means of accessing it at any point.

Consequently, your research data is not personal data that we process, and no data subject request is needed to have it erased — it never left your machine.

2. What we actually collect

We do not collect special categories of data (Article 9 GDPR), we do not create user accounts, and no registration is required to use any tool.

3. Legal bases for processing

4. Cookies and similar technologies

We use three categories:

Your reference list in the citation generator is also stored in localStorage on your device. It is never transmitted to us and you can clear it with the "Clear" button.

5. Google AdSense and advertising

This site uses Google AdSense to display advertising and fund its free operation. In that context:

6. Third-party processors

Each of these services has its own privacy policy, which we recommend reviewing.

7. International data transfers

Our hosting and advertising providers process data in the United States and other countries outside the EEA. Where personal data of EEA or UK residents is transferred, those providers rely on the European Commission's Standard Contractual Clauses and, where applicable, on their certification under the EU–US Data Privacy Framework, as set out in their own documentation. Brazil, where the controller is established, has not received an EU adequacy decision; transfers to us therefore rely on the same safeguards or, for the contact form, on your explicit request.

8. Data sharing and sale

We do not sell, rent or trade personal data. For the purposes of the CCPA/CPRA, we note that the use of advertising cookies may constitute "sharing" of personal information for cross-context behavioural advertising. California residents may exercise their right to opt out through the cookie preferences banner or by enabling the Global Privacy Control signal in their browser, which we honour.

9. Retention

Technical logs are retained for our hosting provider's standard period. Contact form messages are kept only as long as needed to handle your enquiry, and no longer than 24 months. Consent records are kept for 12 months, after which the banner will ask again. Research data loaded into the tools is never retained, because it never leaves your device.

10. Your rights

Depending on where you live, you have the right to:

To exercise any of these, write to us through the contact page. We respond within one month, as required by Article 12(3) GDPR. We do not charge a fee and we will not discriminate against you for exercising your rights.

If you believe we have handled your data unlawfully, you may lodge a complaint with the data protection authority of your country of residence — in the UK, the Information Commissioner's Office; in Brazil, the ANPD.

11. Children

This site is intended for undergraduate and postgraduate students and researchers. We do not knowingly collect data from children under 16 (or under 13, where local law sets that threshold). If you believe a child has provided us with personal data, contact us and we will delete it.

12. Security

The site is served exclusively over HTTPS. Because there is no user database and no file upload to any server, the attack surface is substantially reduced by design. No system is perfectly secure, but the data we could lose in a breach amounts to server logs.

13. Changes

We may update this policy. Material changes will be signalled by the update date at the top of this page, and where required by law we will seek fresh consent.

14. Contact

Questions about privacy or requests to exercise your rights: contact page.