Back to the Bookstore
Legal & Privacy

Privacy
Policy.

Company

Mira Cultural LTDA

CNPJ

46.892.373/0001-15

Last updated

January 2025

Legislation

LGPD — Lei 13.709/2018

This Privacy Policy describes how Mira Cultural LTDA ("we," "our" or "the Bookstore") collects, uses, stores and protects the personal data of our customers, website visitors, event participants and all others with whom we interact in the course of our book retail activities in Belo Horizonte, MG.

We are fully committed to compliance with the Brazilian General Data Protection Law — LGPD (Lei nº 13.709/2018), the Brazilian Consumer Protection Code — CDC (Lei nº 8.078/1990) and the tax legislation applicable to retail trade in the State of Minas Gerais.

i.

Introduction and Scope

This Policy applies to all personal data processed by Mira Cultural — including data of customers who make in-store purchases, persons who contact us by phone, email or WhatsApp, website visitors, participants in literary events and anyone whose data is processed in connection with our activities.

By purchasing books, participating in events, contacting us or visiting our website, you acknowledge having read and understood this Policy.

ii.

Identity of the Controller

Company name: Mira Cultural LTDA
CNPJ: 46.892.373/0001-15
Activity (CNAE): Comércio Varejista de Livros (Retail Trade of Books)
Address: Av. Augusto de Lima, 407, Sala 1609, Centro, Belo Horizonte — MG, CEP 30190-912, Brasil
Email: privacidade@miracultural.com.br
iii.

Personal Data We Collect

In connection with our book retail activities, we process personal data in the following categories:

  • In-store purchase data: Name and CPF for NF-e or NFC-e issuance when requested by the customer — we do not require CPF for purchases below the legal threshold.
  • Customer registration and loyalty data: Full name, email, phone/WhatsApp and literary preferences — collected for communications, book clubs and personalised recommendations.
  • Contact and service data: Messages sent by email, WhatsApp or form — name, phone, email and content of communication for handling requests and orders.
  • Event participant data: Name, email and phone of those registered for launches, readings and book clubs — for list management and event communications.
  • Book club / subscription data: Full name, delivery address (where applicable), email and literary preferences for personalised curation.
  • Technical website data: IP address, browser type, pages visited and access times — for analysis and experience improvement.

We do not store payment card data directly — electronic transactions are processed by PCI-DSS certified payment platforms.

iv.

Purpose and Legal Basis

PurposeLegal Basis (LGPD)
Issuing NF-e / NFC-e on book salesLegal obligation — SEFAZ-MG; Federal tax legislation
Processing orders, special requests and enquiriesPerformance of contract (Art. 7º, V)
Customer registration and book club managementConsent (Art. 7º, I); Performance of contract
Personalised literary curation and recommendationsConsent; Legitimate interest (Art. 7º, IX)
Communications about events, launches and newsConsent (opt-in); Legitimate interest
Managing event registrationsPerformance of contract; Consent
Upholding consumer rights under the CDCLegal obligation (Art. 7º, II); CDC Art. 49
Tax compliance — ISSQN, ICMS/MG, SEFAZ-MGLegal obligation (Art. 7º, II)
Website analysis and improvementLegitimate interest; Consent (cookies)
Fraud prevention and defence in legal proceedingsLegitimate interest; Exercise of rights (Art. 7º, VI)
v.

Data Sharing

We do not sell or commercially exploit customers' personal data. Sharing occurs only in the following situations:

  • SEFAZ-MG / Federal Revenue (Receita Federal): Tax data for NF-e and NFC-e issuance and compliance with applicable federal and state tax obligations for book retail in Minas Gerais.
  • Publishers and distributors (special orders): To fulfil orders for out-of-stock titles — minimum data shared (name and contact) only when strictly necessary.
  • Payment platforms: For processing electronic transactions — operated under PCI-DSS standards, with no access to purchase history for their own commercial purposes.
  • Technology service providers: Email marketing, CRM and event management platforms — under data processing agreements and access limited to contracted purposes.
  • PROCON-MG: When required in a consumer dispute mediation procedure under the CDC.
  • Legal authorities: When required by a competent judicial or administrative order.
Note on books and reading preferences: Customers' reading preferences and purchase history are handled with special discretion. We do not share them with third parties for marketing purposes without the data subject's explicit and specific consent.
vi.

International Transfers

Primary storage of customer data is carried out in Brazil. Email marketing or website analytics platforms that operate on servers outside Brazilian territory do so only under the guarantees of Art. 33 of the LGPD or recognised adequacy mechanisms. Details of any such transfers are available upon request via the contact in Section xiv.

vii.

Retention Periods

  • Tax records (NF-e / NFC-e): Minimum 5 years under federal tax legislation (CTN, Art. 174) and SEFAZ-MG requirements.
  • Sales records for consumer rights (CDC): Up to 2 years for post-sale support on book purchases; minimum 5 years for durable goods under CDC Art. 26, II.
  • Customer registration and reading preferences: While the registration remains active, or until a deletion request is made. Automatically deleted after 3 years of inactivity.
  • Event registrations: Up to 6 months after the event, unless further communication was authorised.
  • Book club / subscription data: Duration of the subscription plus 1 year for support and queries.
  • Communications and emails: Up to 2 years from the last interaction.
  • Website analytics: Aggregated and anonymised after 12 months.
viii.

Security Measures

  • Access to the customer database restricted to bookstore staff with an operational need;
  • Encryption in transit (HTTPS) for the website and digital communications;
  • PCI-DSS certified payment platforms — card data is never stored by Mira Cultural;
  • Secure credentials and authentication for CRM and email marketing platforms;
  • Incident response procedures and breach notification in accordance with LGPD Art. 48.
ix.

Your Rights under the LGPD

  • Confirmation and Access (Art. 18, I–II): Confirm whether we process your data and receive a copy.
  • Correction (Art. 18, III): Request correction of inaccurate or outdated data.
  • Anonymisation / Blocking / Deletion (Art. 18, IV): Request restriction or deletion of unnecessary data.
  • Portability (Art. 18, V): Receive your data in a structured, interoperable format.
  • Deletion of consent-based data (Art. 18, VI): Request deletion of data processed on the basis of consent — e.g. registration, reading preferences, event lists.
  • Information on sharing (Art. 18, VII): Find out which entities your data has been shared with.
  • Withdrawal of Consent (Art. 8º, §5º): Withdraw consent for marketing communications at any time.
  • Complaint to the ANPD (Art. 18, §1º): Lodge a complaint at www.gov.br/anpd.

We respond within 15 business days. Deletions may be limited by legal tax retention obligations for NF-e records — we will always explain the reasons for any limitation.

x.

Cookies and Tracking

Our website may use cookies for essential functionality and aggregated performance analysis. We do not use behavioural tracking cookies for advertising purposes without prior consent. Preferences can be managed through browser settings.

xi.

Protection of Minors

Mira Cultural offers a children's and young adult section and organises events for younger readers. We observe the following child protection guidelines:

  • For registrations at events intended for children under 13, we require authorisation and contact data from a legal guardian — consent is given by the guardian, not the child (LGPD Art. 14, §1º).
  • For adolescents aged 13 to 17, we collect data with their own consent, communicating with the guardian where appropriate.
  • We do not send marketing communications directly to children under 13 without explicit guardian consent.
  • We do not build reading preference profiles for children for commercial purposes.
xii.

Sensitive Data & Reading Privacy

Reading preferences — such as interest in works on religion, politics, sexual orientation, health or other sensitive subjects — may indirectly reveal sensitive personal data about the customer (LGPD Art. 5º, II).

Mira Cultural treats reading preferences with special discretion:

  • Reading preferences collected for curation and personalised recommendations are used exclusively for that purpose — never shared with third parties for commercial or marketing purposes;
  • Customers may request deletion of their preference history at any time, without any impact on the purchase service;
  • We do not make inferences about customers' sensitive characteristics based on purchase history.
Freedom to Read: We believe in the reader's privacy as a fundamental value. The choice of a book is personal — we treat this data with the same respect that a good bookseller has always devoted to the confidentiality of their customer's choices.
xiii.

Updates to this Policy

This Policy may be updated to reflect changes in our activities, the LGPD, ANPD guidance or CDC regulations. Material changes will be communicated by email to registered customers with reasonable advance notice.

xiv.

Contact & Data Protection Officer

All privacy requests, questions and complaints should be directed to our Data Protection Officer (Encarregado — LGPD Art. 41):

Privacy Contact

CompanyMira Cultural LTDA
CNPJ46.892.373/0001-15
AddressAv. Augusto de Lima, 407, Sala 1609, Centro, Belo Horizonte — MG, CEP 30190-912, Brasil
WhatsApp+55 (31) 9 0000-0000
HoursMon–Fri: 09:00–19:00 · Sat: 09:00–17:00
ResponseWithin 15 business days of receipt.
You also have the right to lodge a complaint with the national data protection authority:
ANPD — Autoridade Nacional de Proteção de Dados
www.gov.br/anpd