IN COMPLIANCE WITH BRAZILIAN LAW NO. 13,709/2018 (LGPD)
1. IDENTIFICATION OF THE CONTROLLER
1.1. [LICENSOR’S CORPORATE NAME], enrolled with the Brazilian Corporate Taxpayers’ Registry (CNPJ) under No. [CNPJ], with registered office at [ADDRESS] (“Controller”), is responsible for the processing of personal data described in this Privacy Policy (“Policy”), acting as controller, within the meaning of art. 5, VI, of Law No. 13,709/2018 (LGPD).
1.2. The Controller maintains a data protection officer responsible for personal data processing, whose identity and contact information are disclosed in Section 11 of this Policy, in compliance with art. 41 of the LGPD.
2. OF THE PURPOSE AND SCOPE
2.1. This Policy applies to the processing of personal data carried out through the Controller’s institutional website and in connection with the provision of the IT infrastructure monitoring software licensed to the Controller’s business customers (“Software”).
2.2. With respect to personal data incidentally captured by the Software within the licensed customer’s Monitored Environment, the specific provisions of Section 7 of the Software License Agreement (EULA) apply, under which the licensed customer acts as controller of such data and the Controller under this Policy acts as processor, pursuant to arts. 5, VI and VII, and 39 of the LGPD. This Policy therefore primarily addresses personal data processed by the Controller in its capacity as controller — that is, data of website visitors and of customer representatives.
3. OF THE PERSONAL DATA COLLECTED
3.1. The Controller may collect the following categories of personal data:
a) identification and contact data of representatives of customers and prospective customers (name, job title, corporate e-mail, telephone number), provided through contact forms, registration, or in connection with the contractual relationship;
b) website browsing data (IP address, device type, pages visited, cookies, and similar identifiers), as detailed in Section 10;
c) personal data incidentally processed in connection with the provision of the Software, within the terms and limits of clause 2.2 above.
4. OF THE PURPOSES OF PROCESSING
4.1. The personal data referred to in Section 3 are processed for the following purposes: (i) enabling commercial contact and relationship management with customers and prospective customers; (ii) enabling the creation and management of registrations and user accounts; (iii) complying with contractual and legal obligations; (iv) improving the website browsing experience; and (v) preventing fraud and ensuring the security of operations.
5. OF THE LEGAL BASES FOR PROCESSING
5.1. The Controller’s processing of personal data is based on the legal hypotheses set forth in art. 7 of Law No. 13,709/2018:
“Art. 7. The processing of personal data may only be carried out in the following circumstances: I – upon consent of the data subject; II – for compliance with a legal or regulatory obligation by the controller; […] V – where necessary for the performance of a contract or preliminary procedures related to a contract to which the data subject is a party, at the data subject’s request; […] IX – where necessary to serve the legitimate interests of the controller or a third party, except where the data subject’s fundamental rights and freedoms requiring personal data protection prevail; or X – for credit protection purposes, including as provided under applicable legislation.” (Free translation — Portuguese original prevails.)
5.2. As a general rule, the processing of customer representatives’ data is based on the performance of preliminary procedures or of the contract (item V) and on the Controller’s legitimate interest in maintaining a business relationship (item IX); the processing of browsing data for essential website functions is likewise based on legitimate interest; and the processing of non-essential cookies, where applicable, is based on consent (item I), as set forth in Section 10.
6. OF THE APPLICABLE PRINCIPLES
6.1. The Controller’s processing of personal data observes good faith and the principles set forth in art. 6 of the LGPD:
“Art. 6. Personal data processing activities shall observe good faith and the following principles: I – purpose […]; II – suitability […]; III – necessity […]; IV – free access […]; V – data quality […]; VI – transparency […]; VII – security […]; VIII – prevention […]; IX – non-discrimination […]; X – accountability […].” (Free translation — Portuguese original prevails.)
7. OF DATA SHARING
7.1. The Controller may share personal data with IT infrastructure service providers (hosting, cloud computing, e-mail and CRM tools), strictly to the extent necessary for the performance of its activities, subject to contractual confidentiality and security obligations.
7.2. The Controller does not sell or trade personal data with third parties for advertising purposes.
8. OF INTERNATIONAL DATA TRANSFER
8.1. Should the Controller use service providers with infrastructure located outside Brazilian territory, any international transfer will comply with the hypotheses set forth in art. 33 of the LGPD, through adequate contractual clauses or an equivalent instrument recognized by Brazil’s National Data Protection Authority (ANPD).
9. OF DATA RETENTION AND DELETION
9.1. Personal data will be retained for the period necessary to fulfill the purposes for which it was collected, subject to legal retention obligations (tax, accounting, regulatory), and will thereafter be deleted, anonymized, or blocked, pursuant to arts. 15 and 16 of the LGPD.
10. OF COOKIES AND TRACKING TECHNOLOGIES
10.1. The Controller’s website uses cookies essential to its operation and, where applicable, analytics and performance cookies, the use of which is subject to the user’s consent, manageable through a banner or preference panel available on the Site.
11. OF DATA SUBJECT RIGHTS
11.1. Pursuant to art. 18 of the LGPD, the data subject has the right to obtain from the Controller, at any time and upon request:
“Art. 18. The data subject has the right to obtain from the controller, with respect to the data subject’s data processed by the controller, at any time and upon request: I – confirmation of the existence of processing; II – access to the data; III – correction of incomplete, inaccurate, or outdated data; IV – anonymization, blocking, or deletion of unnecessary, excessive data, or data processed in violation of this Law; V – portability of data to another service or product provider […]; VI – deletion of personal data processed with the data subject’s consent, except in the cases provided for in art. 16 of this Law; VII – information on the public and private entities with which the controller has shared data; VIII – information on the possibility of not providing consent and the consequences of refusal; IX – withdrawal of consent, pursuant to art. 8, paragraph 5, of this Law.” (Free translation — Portuguese original prevails.)
11.2. Such rights may be exercised by contacting the data protection officer identified in Section 12 of this Policy.
12. OF THE DATA PROTECTION OFFICER
12.1. In compliance with art. 41 of the LGPD:
“Art. 41. The controller shall appoint a person responsible for personal data processing. Paragraph 1. The identity and contact information of such person shall be publicly disclosed, in a clear and objective manner, preferably on the controller’s website. Paragraph 2. The duties of such person consist of: I – receiving complaints and communications from data subjects, providing clarifications, and adopting appropriate measures; II – receiving communications from the national authority and adopting appropriate measures; III – guiding the entity’s employees and contractors regarding practices to be adopted in relation to personal data protection; and IV – performing any other duties determined by the controller or established in supplementary regulations.” (Free translation — Portuguese original prevails.)
12.2. The Controller’s data protection officer may be contacted at: [NAME OF DATA PROTECTION OFFICER] — [CONTACT E-MAIL].
13. OF AMENDMENTS TO THIS POLICY
13.1. This Policy may be revised and unilaterally amended by the Controller at any time, upon publication of the updated version on the website at least thirty (30) days in advance.
14. OF CONTACT AND JURISDICTION
14.1. Questions, requests, or complaints related to this Policy may be directed to the data protection officer identified in Section 12.
14.2. The courts of the Judicial District of São Paulo, Capital of the State of São Paulo, Brazil, are elected to settle disputes arising from this Policy, without prejudice to the competence of Brazil’s National Data Protection Authority (ANPD).
Region BR not activated for privacy-statement.