Privacy Policy

1. OBJECTIVE

Grupo Sarlo is committed to the protection of personal data, and treating it in a responsible, transparent, ethical, and secure manner is an essential value for us. This Privacy Policy (or simply “Policy”) explains how Grupo Sarlo, as the Personal Data Controller, processes Personal Data to perform its activities, whether belonging to employees, customers, or third parties, including our website and social media.

We recommend a careful reading of this document, emphasizing that it must be interpreted in Good Faith and in conjunction with other laws (CLT, Consumer Code, Civil Code, Access to Information Law, among others), documents, contracts, or privacy clauses that accompany it, as the case may be, and without prejudice to the professional secrecy applicable to the relationship.

2. CONCEPTS

Personal data: Any information related to an identified or identifiable natural person.

Controller: For the purposes of applicable legislation, the controller is the one responsible for decisions regarding the processing of personal data.

Processor: A natural or legal person who performs the processing of personal data under the orders of the Controller.

Data Subject: You, the natural person to whom the personal data being processed refers.

Processing means any operation performed with Personal Data, such as: collection, production, reception, classification, use, access, reproduction, transmission, distribution, processing, filing, storage, deletion, evaluation or control of information, modification, communication, transfer, dissemination, or extraction.

Data Protection Officer (DPO): the person responsible for mediating communication between data subjects, the controller, and the National Data Protection Authority.

National Data Protection Authority (ANPD): the public administration body responsible for ensuring and supervising compliance with LGPD provisions and for applying sanctions provided by law.

2. HOW WE USE YOUR DATA

  • When you use our website and/or Customer Service (SAC);
  • When you provide us with your data (e.g., sending a resume or email);
  • When you purchase a product on our website;
  • When a person becomes an employee of the company;
  • When we establish partnerships for service provision (e.g., health insurance);
  • Conducting advertising campaigns for Grupo Sarlo Better;
  • Providing services associated with the products we market;
  • When you exercise your rights as a data subject.

3. PERSONAL DATA PROCESSED

Within the limits permitted by applicable legislation, we may process the personal data described below, depending on each situation:

  • Registration data: name, date of birth, gender, ID (RG), Tax ID (CPF), Work Booklet (CTPS), residential or business address, residential, business, and cell phone numbers, email, profession, occupation, marital status, nationality, place of birth, among others.
  • Sensitive Personal Data: biometric data (photo/image and fingerprint), health-related data, union membership, and race.
  • Third-party data: parentage, representatives, represented parties, guarantors, attorneys, collaborators, partners, or beneficiaries of products and services, such as insurance, pension plans, credit cards, and payments.
  • Social media and platform data: interactions you may have with our social networks.
  • Financial situation data: we may access data regarding your financial or credit situation, such as income, assets, credit defaults, including detailed positive credit registry data or Central Bank Credit Information System data, in accordance with applicable legislation.

4. MINORS

 

Our company may collect and process personal data of minors (persons under 18 years of age) in cases of apprentices, interns, dependents, or beneficiaries.

5. PURPOSES FOR WHICH WE PROCESS YOUR PERSONAL DATA

 

We may process Personal Data and other information for various purposes related to our activities, as per the examples described below:

  • Complying with Legal or Regulatory Obligations

Your Personal Data will also be used to meet obligations set forth in law, government agency regulations, tax authorities, the Judiciary, and/or other competent authorities, including internal auditing and compliance;

  • Performance of contract or preliminary procedures to the contract

We may use the data you provided to fulfill the stated purpose, regardless of the legal relationship (civil, labor, consumer, or other), including stages before or after contracting. For example, we may use your data for candidate selection, hiring employees, providing a service, or even a simple purchase and sale, as well as to serve our customers, potential customers, and third parties, handling questions, complaints, claims, requests, and support through our service channels, enabling your contact with us whenever necessary and vice versa.

  • Allowing the Regular Exercise of Our Rights

Even after the termination of the contractual relationship, we may process some of your Personal Data to comply with legal obligations, observing statute of limitations periods, including as evidence in judicial, administrative, or arbitration proceedings.

  • Regular exercise of rights in judicial, administrative, or arbitration proceedings

Personal data may also be used by Sarlo Better so that it can exercise its constitutional right to full defense and adversarial proceedings (judicial, administrative, or arbitration).

  • For the protection of life or physical safety of the data subject or third parties;

Data processing may occur when indispensable for the protection of life or physical safety of the data subject or third parties, even without the subject’s consent, as the greatest good of the natural person is life and the protection of their physical integrity, which are grounded in the Federal Constitution, with implications for human dignity.

  • Promoting Our Activities and Expanding Product and Service Marketing Offers

Additionally, we may also process data for advertising communications, news, offers, and promotions, OR for the provision of services associated with the products we market. Conducting satisfaction surveys and understanding the customer journey during the purchase process. In these cases, if you feel uncomfortable and no longer wish to receive any advertising information, you can suspend them at any time. As a rule, all our electronic communications offer you this choice.

  • Credit protection

Activities related to credit protection, such as profile analysis, credit risk assessment and management, financial and asset situation evaluation, collection, credit assignment, activities related to information and consultation with credit protection entities and positive registries, among others;

Eventually, we may process your data to prove you are who you say you are and to prevent fraud.

  • Consent

This is the free, informed, and unequivocal expression by which the data subject agrees to the processing of their personal data for a specific purpose that does not fall under any of the previous alternatives.

Eventually, when strictly necessary, we may process your data to prove you are who you say you are and to prevent fraud.

6. SHARING

Our company will sometimes need to share your personal data with third parties. Situations involving the sharing of your information include:

  • With partner companies, service providers, auditors, or suppliers that we use to provide support to our activity, helping us operationalize our business, aiming to improve our quality and efficiency while maintaining competitiveness with lower costs.
  • With authorities, government entities, or Public Authorities to comply with legislation, respond to a court order, or if there are threats to someone’s safety or physical integrity.

  • In the case of corporate transactions and/or operations involving the Organization, in which case the transfer of information will be necessary for the continuity of business activities;
  • Targeted advertising. We partner with companies specializing in advertisements/publicity. Some of these ads are tailored to your interests based on collected information. You can opt out of receiving this type of advertising and can request to stop receiving emails by accessing the link in the footer.
  • We may share your personal information in other ways when the data subject exercises the right to portability or with your consent. For example, after the contract, providing references to a future employer.
  • To safeguard and protect the rights of Grupo Sarlo Better, we reserve the right to access, read, preserve, and disclose any Data we believe is necessary to comply with a legal obligation or a court order; enforce this Privacy Policy and other agreements/contracts; protect the rights, property, or safety of Grupo Sarlo Better, our employees, customers, providers, suppliers, or others.

7. RETENTION PERIOD

We keep your personal information for the period necessary or permitted based on the purposes for which it was obtained. The criteria used to determine retention periods include, but are not limited to: (a) the period of time during which we have a relationship with you; (b) compliance with a possible legal obligation to which we are subject; and (c) whether retention is advisable based on our legal position (to exercise rights in judicial or administrative proceedings).

Thus, whenever applicable, we perform the proper purging of unnecessary or excessive personal data;

8. COOKIES

What are cookies?

They are small files that temporarily store user preferences identified when visiting a particular site, allowing data related to the computer or other device used by the User in previous navigations to be remembered, optimizing their interaction with the platform.

Essential cookies:

Some cookies are essential for the functioning of platforms and cannot be disabled without generating negative consequences for navigation.

Non-essential cookies:

Cookies called non-essential, although not mandatory, allow for the optimization of the User experience, providing features such as remembering preferences, search terms, and product/search history, allowing for customized navigation.

In short:

You can control the use of non-essential cookies through your browser settings (enabling or disabling them), but this may affect the proper functioning of our platforms.

9. SECURITY

No transmission of information is completely secure, as it will always be susceptible to technical failures, malware, and/or similar actions. However, our organization adopts market-standard security mechanisms and procedures to protect personal data.

Furthermore, we direct efforts toward training and raising awareness among our employees and partners about the importance of data protection, in order to keep them updated on market best practices and the importance of implementing internal flows such as access control and the duty of confidentiality, which also includes:

  • Protection against unauthorized access;
  • Restricted access to the location where personal information is stored; and,
  • Adoption of procedures so that agents, employees, and partners who process personal data commit to maintaining absolute secrecy of the information, adopting best practices for handling this data, as determined in corporate policies and procedures;
  • Maintaining a governance and privacy program applied to its activities and governance structure, constantly updated.

In the remote event of such an episode, the company guarantees full effort to remedy the consequences of the event, always ensuring proper transparency to you.

10. DATA SUBJECT RIGHTS

You have several rights regarding your personal data as provided by law and may, at any time, provided you prove you are indeed the Data Subject: a) request free access to the data we store concerning you; b) its rectification, if necessary; c) deletion or limitation of the use of personal data, except in cases provided by law; d) portability; e) revoke consent; f) anonymization or, g) object to its processing, except in cases provided by law. You may exercise these rights by written request sent to the email relacionamento@sarlobetter.com.br

We emphasize that we may keep some data and/or continue to perform Processing, even in the case of a request for deletion, objection, blocking, or anonymization, in some circumstances, such as to comply with legal, contractual, and regulatory obligations, to safeguard and exercise the rights of Grupo Sarlo Better, employees, and customers, for the prevention of illicit acts, and in judicial, administrative, and arbitration proceedings, including third-party questioning about their activities and in other cases provided by law.

11. CHANGES TO THIS POLICY

Following a standard of continuous improvement, we may change this Data Privacy Policy at any time, at our discretion, or due to relevant legislation updates/changes or necessity. These changes will be duly made available and, if they represent a substantial change in how your data will be processed, Grupo Sarlo Better will maintain contact based on the data provided.

12. COMPLAINTS AND QUESTIONS

In case of questions or for more information related to the processing of your personal data and the rights granted to you by applicable legislation, please contact the Data Protection Officer via the email mentioned above.

If you have any criticism, suggestion, or praise regarding this policy, please inform us via the email above, remembering that the user also has the right to file a complaint with the National Data Protection Authority as provided by law.

We will be pleased to assist you.

Published on: 10/14/2022

Revised on: 10/31/2022