Privacy Policy
How Regalia handles your personal data
In line with its duty of transparency, and in order to uphold the commitment of REGALIA TECNOLOGIA E PARTICIPAÇÕES LTDA to its clients and partners, this Privacy Policy (the “Policy”) has been drawn up.
Document D.GSI.09 · Revision 01 · 08/08/2023 · Approved by Francisco Farias · Courtesy translation: the Portuguese version prevails.
Scope
This Policy applies to all services provided by REGALIA and aims to ensure that everyone knows which Personal Data REGALIA collects, how that information is processed, and what rights and choices you have regarding your Personal Data.
REGALIA reserves the right to amend the provisions of this Policy. Any changes will be published through the company’s official communication channels. REGALIA therefore recommends consulting the most recent version of the Policy in case of doubt.
1 · Definitions
For the purposes of this Privacy Policy, the following definitions apply:
- Personal Data — any information which, alone or together with other information, makes it possible to identify a natural person, whether directly (for example, through their name or CPF) or indirectly (for example, by reference to an identification number or to a combination of characteristics or information).
- Sensitive Personal Data — data revealing sensitive information about natural persons concerning racial or ethnic origin, religious belief, political opinion, membership of a trade union or of a religious, philosophical or political organisation, data concerning health or sex life, and genetic or biometric data.
- Processing — any use of Personal Data, including for example collection, access, retention, alteration, transfer or any other form of use.
- Controller — the natural or legal person, governed by public or private law, responsible for decisions regarding the Processing of Personal Data.
- Processor — the natural or legal person, governed by public or private law, who carries out the Processing of Personal Data on behalf of the Controller.
- Data Subject — the natural person to whom the Personal Data being processed relates.
- Data Protection Officer (DPO) — the person appointed by the Controller to act as the channel of communication between the Controller, the Data Subjects and the Brazilian National Data Protection Authority (ANPD).
2 · What data Regalia collects about you
In general, REGALIA collects Personal Data from three sources: from Clients, from third parties, and through the course of REGALIA’s own activities.
- Clients — any Personal Data actively provided by the Client when making contact, completing a contract or updating their details, including registration data such as full name, RG, CPF, address, telephone, email, marital status, occupation and date of birth.
- Third parties — REGALIA may receive information from third parties about your interest in the company’s products or services. However, we will only make contact after verifying that the referral was made with your knowledge or authorisation. The data collected includes name, telephone and the product or service of interest.
- Regalia — Personal Data arising from your interactions with REGALIA’s activities, such as records of interactions carried out with you by text message, email and telephone, feedback from satisfaction surveys, service records and logs in the Regalia system.
3 · How Regalia uses and shares your personal data
It is important that you understand the purposes for which REGALIA collects your Personal Data and why it is necessary for the company’s operations. The situations in which REGALIA processes your Personal Data are set out below:
- Contracting and provision of services to Clients — the data needed to perform contracts and deliver the contracted services is processed: full name, RG, CPF, address, telephone, email, marital status, occupation and date of birth.
- Payment processing — REGALIA may use Personal Data to process payments and issue invoices: name, CPF, RG, telephone, email, address and financial data.
- Client response service — REGALIA processes the Personal Data provided at registration when you contact the company with questions or requests about the services provided: name, CPF, address, email, telephone and details of the request.
- Regalia’s legitimate interest — on certain occasions REGALIA will need to process Personal Data in order to prevent fraud, provide technical and operational support and carry out satisfaction surveys: name, CPF, RG, telephone, occupation and contract number.
- Advertising purposes — REGALIA may collect Personal Data with your consent for advertising purposes. The data used differs from campaign to campaign, but is generally name, telephone, CPF, RG, date of birth and address.
- Compliance with legal and regulatory obligations — your Personal Data may be needed for REGALIA to comply with legal and regulatory requirements, whether judicial or administrative, imposed by competent authorities and government bodies.
- Regular exercise of rights in judicial, administrative or arbitration proceedings — REGALIA may use Personal Data to bring proceedings and to defend its rights and those of third parties. For that purpose it may retain Client data after the service has ended, for the retention period set by Brazilian law.
Where consent is required, if the purpose of the Processing of Personal Data changes in ways incompatible with the original consent, REGALIA will inform the Data Subject in advance of those changes, and the Data Subject may withdraw consent if they disagree with them.
Where the Processing of Personal Data is a condition for the provision of a service or for the exercise of a right, the Data Subject will be prominently informed of that fact and of the means by which they may exercise the rights listed in section 7 of this Policy.
4 · Where Regalia stores your data
Client and partner information is stored by REGALIA on its own servers or on third-party servers.
Client information is kept confidential, and any REGALIA employee or service provider who comes into contact with it undertakes not to misuse it, nor to use it in any way other than as set out in this Policy.
REGALIA applies all reasonable market efforts to guarantee the security of its systems in safeguarding that data, as detailed in section 6 of this Policy.
5 · Deletion of personal data
Information collected by REGALIA will be deleted from its servers once it is no longer necessary for the purposes for which it was collected.
If a Client or partner wishes to request the amendment, correction or deletion of the data collected, they may get in touch at [email protected], setting out their request. REGALIA will make every effort to deal with all requests in the shortest possible time.
In the case of a deletion request, REGALIA will observe the data retention period set by Brazilian law and may retain information in order to comply with a legal or regulatory obligation, for REGALIA’s exclusive use of anonymised data, and for the exercise of its rights in judicial or administrative proceedings.
6 · Information security
REGALIA adopts technical and administrative measures to protect your Personal Data and ensure compliance with data protection rules. These measures are reviewed and improved periodically to ensure that best practice and technical standards are followed, and include encryption, physical and technical protection of information, data access management, internal information security policies, network security systems, user education and awareness, malware prevention, monitored and up-to-date security patching of equipment, an incident management system and equipment monitoring.
In addition to all the measures listed above, REGALIA has internal procedures and teams ready to detect and respond to possible security incidents, in order to mitigate risks and protect the privacy of Data Subjects.
To ensure these efforts are effective, REGALIA relies on the cooperation of Clients and Partners: when contacting REGALIA by email, WhatsApp or telephone, only share Personal Data if you are certain you are using the official contact details, so as to avoid exposing yourself to risk.
REGALIA’s transactional emails are sent from the subdomain @regaliatec.net.br. Client service emails are sent from the subdomain @regaliatec.com.br.
7 · Rights of data subjects
In accordance with data protection regulations, REGALIA respects and guarantees that Clients and partners, as Data Subjects, may exercise their rights in relation to their Personal Data. Those rights include, but are not limited to:
- Access — to confirm the existence of Processing of Personal Data and to request access to your Personal Data and to information about the Processing.
- Rectification — to request the correction of any inaccurate, incomplete or out-of-date Personal Data.
- Objection, erasure or blocking — to object to Processing activities and to request the anonymisation, erasure and blocking of your Personal Data where it is processed in breach of the Brazilian General Data Protection Law (Law no. 13.709/2018) or where it is considered unnecessary or excessive.
- Portability — to request the portability of your Personal Data to another provider of similar services, with the exception of data already anonymised or data that would infringe REGALIA’s trade and industrial secrets.
- Withdrawal of consent — to withdraw any consent at any time, where REGALIA processes your Personal Data on the basis of consent, and to request the erasure of that data.
- Review — to request the review of automated decisions that may affect your interests.
- Information — to request information about the possibility of not giving your consent, and to be informed of the consequences of refusing.
- Opt-out — to opt out if you no longer wish to receive advertising content from REGALIA by email or message.
You may exercise your rights at any time by making a specific request through [email protected]. REGALIA will endeavour to respond in the shortest time possible, save for justifiable factors, such as the complexity of the action requested, which may delay or prevent a rapid response.
Finally, Data Subjects should be aware that their request may not be granted if it does not meet formal requirements, such as proof of identity, or legal requirements — for example, a request to delete Personal Data which REGALIA is legally permitted to retain.
8 · Cookies
What exactly are cookies
Cookies are small text files that a website places on the user’s computer or mobile device when they visit the page, through the internet browser. Installing cookies helps the site recognise the user’s device when they return to the page. In this Policy, the term “cookies” refers to all files that collect information in this way.
The cookies used in our systems do not gather data that identifies the user, but rather generic information. At any time, through the browser, the user may choose to be notified when cookies are received and to block them from entering the system. Note that refusing the use of cookies on the site may make it impossible to access certain areas or to receive personalised information.
What they are used for
Cookies play a part in assessing the usefulness, interest and frequency of use of websites, making browsing faster and more effective and removing the need to enter the same information repeatedly.
Which categories and types we use
- Functionality cookies — used to remember the user’s preferences. For example, they remove the need to type a username on every visit, and they preserve preferences about how the site is used, avoiding the need to reconfigure the site on each visit.
- Third-party cookies — used to assess the success of applications on our site.
- Permanent cookies — stored at browser level on access devices and activated every time the user makes a new visit to the site.
- Session cookies — temporary, remaining in the browser until the user leaves the site. The information obtained makes it possible to identify problems and provides an improved browsing experience.
After granting authorisation for the use of cookies, the user may disable our cookies partially or entirely. All browsers allow cookies to be accepted, refused or deleted by selecting the appropriate settings in the “options” or “preferences” menu. Note that disabling cookies may stop certain web services from working correctly, affecting browsing on the site partially or completely.
9 · Contact
Data Protection Officer (DPO)
For any further questions or requests, please contact the Data Protection Officer through the following channels:
[email protected]
+55 81 3038.0848
Rua Antônio Lumack do Monte, 128, sala 106
Empresarial Center III
Boa Viagem, Recife – PE · CEP 51.020-350