Policy on Privacy and Personal Data Protection

  1. PURPOSE

The purpose of this Policy on Privacy and Personal Data Protection (the “Policy”) is to establish the commitment of Pinheiro Guimarães (as defined below) to promoting practices and conduct in compliance with the rules governing the protection of Personal Data (as defined below), including the LGPD (as defined below).

This Policy sets forth a series of guidelines and information for Personnel, Clients, and Data Subjects (as defined below) regarding the Processing (as defined below) of Personal Data carried out by Pinheiro Guimarães, or by Personnel on its behalf.

Every member of Personnel has a duty to familiarize themselves with the contents of this Policy and to adopt the guidelines and practices described herein. Violations of this Policy and failure to comply with the provisions of the LGPD may result in severe administrative, civil, and criminal penalties.

  1. DEFINITIONS

Capitalized terms used in this Policy will have the following meanings:

Associate” means any attorney who is an associate of Pinheiro Guimarães, pursuant to Articles 39 and 40 of the Statute on the Practice of Law and the Brazilian Bar Association (Regulamento Geral do Estatuto da Advocacia e da Ordem dos Advogados do Brasil), enacted by the Federal Council of the Brazilian Bar Association (Conselho Federal da OAB), under the powers conferred by Articles 54(V) and 78 of Law No. 8,906, dated July 4, 1994.

Client” means any individual or legal entity (including its partners, officers, representatives, attorneys-in-fact, service providers, and advisors) that engages, has engaged, or may engage any services rendered by Pinheiro Guimarães.

Personnel” means the Partners, Associates, Employees, Interns, and Vendors, collectively.

Personal Data” means information relating to an identified or identifiable individual that is, has been, or will be processed by Pinheiro Guimarães.

Sensitive Personal Data” means Personal Data concerning racial or ethnic origin, religious belief, political opinion, membership in a trade union or a religious, philosophical, or political organization, data relating to health or sexual life, and genetic or biometric data, when linked to a natural person.

Employee” means any employee hired by Pinheiro Guimarães under an employment agreement governed by the Consolidation of Labor Laws (Consolidação das Leis do Trabalho – CLT).

Intern” means any student under contract with Pinheiro Guimarães pursuant to Law No. 11,788, dated January 25, 2008.

Vendors” means any individual (other than a Partner, Associate, Employee, or Intern) or legal entity engaged by Pinheiro Guimarães to act on behalf of or in the interest of Pinheiro Guimarães, such as accountants, technology service providers, and partner law firms.

Law” or “Legislation” means any and all statutes, laws, decrees, regulations, rules, ordinances, codes, measures, or regulatory requirements issued by any governmental authority.

LGPD” means the General Law on Data Protection, or, Law No. 13,709/2018.

Pinheiro Guimarães” means Pinheiro Guimarães – Advogados.

Partner” means any attorney who holds an equity interest in Pinheiro Guimarães pursuant to its Articles of Association (Contrato Social).

Data Subject” means any individual to whom the personal data being processed pertains, including Personnel and Clients (when they are individuals).

Processing” means any operation carried out with personal data, including but not limited to collection, production, receipt, classification, use, access, reproduction, transmission, distribution, filing, storage, deletion, evaluation or control of information, modification, communication, transfer, dissemination, or extraction.

User” means the Data Subject who accesses the institutional website of Pinheiro Guimarães.

Capitalized terms not defined in this Policy will have the meanings set forth in Article 5 of the LGPD.

  1. DATA PROCESSING

3.1       PROCESSING AGENT

Pinheiro Guimarães may act as either a Controller or a Processor depending on the factual circumstances of the Processing of Personal Data. In either case, the rules set forth in this Policy apply, subject to the provisions of the LGPD and other applicable Laws.

3.2       COLLECTION OF PERSONAL DATA

Pinheiro Guimarães may collect Personal Data from Data Subjects in person or remotely, by postal mail, email, or telephone, in physical or digital form, in writing or verbally, as a result of any of the following acts of, or events relating to, a Data Subject: accessing the Pinheiro Guimarães website, registering for newsletters, submitting resumes for recruitment and selection purposes, submitting messages through the Pinheiro Guimarães website, being included as a member of Personnel, the retaining of Pinheiro Guimarães by Clients, and the rendering of services by Pinheiro Guimarães; and as a result of other events directly or indirectly related to the activities and operations of Pinheiro Guimarães. All collection is and will continue to be carried out by Pinheiro Guimarães in compliance with all requirements of the LGPD and other applicable Laws, and in accordance with the provisions of this Policy.

3.3       DATA PROCESSED

As permitted by applicable Laws and pursuant to this Policy, Pinheiro Guimarães may Process the following Personal Data of Data Subjects, among other data necessary for the purposes set forth in this Policy:

  • Registration and identification data: name, photograph, address, CPF (individual taxpayer ID), identity document, employment card, date of birth, age, email, telephone, profession, marital status, nationality;
  • Family members’ data: name, address, CPF, identity document, telephone, date of birth, age, nationality, marital status, profession;
  • Financial data: compensation, banking information, certificates issued by public entities, assets; and
  • Academic and professional data: professional resume, educational background, and academic transcripts.

3.4       PURPOSE

Pinheiro Guimarães may carry out the Processing of Personal Data of Data Subjects exclusively in connection with the performance of its activities, for the direct or indirect purpose of rendering legal services, as well as for administrative and human resources purposes, including but not limited to:

  • drafting, reviewing, and negotiating contracts and other legal instruments of various types;
  • reviewing documents in the context of legal due diligence for purposes of verifying compliance with applicable legislation and risk analysis within the scope requested by the Client;
  • analyzing, advising in respect of, and managing judicial, administrative, or extrajudicial proceedings;
  • preparing memoranda, legal opinions, and similar documents for the purpose of responding to inquiries submitted by the Client;
  • acting as a liaison between Clients and governmental entities or self-regulatory organizations for the purposes requested by Clients;
  • internal Processing for administrative and financial purposes, such as registration; payment processing; billing; recruitment and selection; recording of lectures, classes, and internal training sessions; and participating in any external or internal compliance audits. Internal processing also includes enrollment and reimbursement under the health plan of Pinheiro Guimarães, as well as the contracting for, migrating to or from, managing, and maintaining the health plan (including the collection, storage, Processing, and sharing of data with the health plan operator, broker, consulting physicians, and other agents involved in the management of the benefit);
  • production and distribution of marketing and promotional materials, including newsletters, articles, event invitations, brochures, presentations, e-books, and social media posts;
  • production of materials for internal and external communications and client outreach, including business cards and email signatures; and
  • compliance with contractual and legal obligations, including for purposes of social security contributions, labor obligations, tax obligations, corporate matters, and accounting.

Given the nature of the activities of Pinheiro Guimarães and its, the Processing of Sensitive Personal Data is carried out on an exceptional, incidental, and de minimis basis, limited strictly to the situations necessary for the proper rendering of the legal services engaged, for compliance with legal or regulatory obligations, and for the legitimate exercise of rights in judicial, administrative, or arbitral proceedings. Furthermore, with respect to Sensitive Personal Data of Personnel and their dependents, such Processing may be carried out by the human resources team and authorized third parties for purposes of enrolling in and operating the health plan.

In carrying out the Processing of Sensitive Personal Data, Pinheiro Guimarães undertakes strictly to observe the principles and requirements established by the LGPD, adopting an appropriate legal basis, technical and administrative measures suitable for the protection of such data, as well as procedures commensurate with the degree of sensitivity of the information subjected to such Processing, so as to ensure its confidentiality, integrity, and security.

3.5       LEGAL BASIS

Pinheiro Guimarães carries out the Processing of Personal Data only with the prior consent of the Data Subject, except in the following cases: (i) where the data is publicly accessible; (ii) where the Processing is carried out on the basis of one of the consent-waiver grounds provided for in Article 7 of the LGPD (such as in order to comply with legal or regulatory obligations); (iii) whenever necessary for the performance of a contract; (iv) where Pinheiro Guimarães is engaged in the regular exercise of its rights; or (v) whenever necessary to serve the legitimate interests of Pinheiro Guimarães.

Regardless of the legal basis, Pinheiro Guimarães will carry out the Processing of Personal Data as necessary and within the limits of the stated purpose. Only Personnel who need to do so for the stated purposes will have access to and carry out the Processing of Personal Data.

3.6       STORAGE

Personal Data subjected to Processing by Pinheiro Guimarães may be stored on its own servers or on third-party servers through cloud services. Personal Data may be stored and retained for the period necessary to fulfill the purpose of the Processing of Personal Data (e.g., for the duration of the services rendered) and for an additional period, as applicable, (i) necessary for Pinheiro Guimarães to comply with legal, regulatory, or contractual obligations (e.g., tax obligations); or (ii) for the legitimate exercise of rights or to serve the legitimate interests of Pinheiro Guimarães (e.g., statute of limitations for indemnification obligations).

3.7       SHARING

Pinheiro Guimarães does not share Personal Data with third parties, except:

  • as authorized by Clients, Personnel, or Data Subjects;
  • if strictly necessary for the rendering of its services or for the performance of its activities;
  • with Personnel who have a strict need to carry out the Processing of such shared Personal Data by reason, directly or indirectly, of the performance of their activities;
  • as a result of external audits of Pinheiro Guimarães, including for purposes of “know your partner” and “know your client” processes to which the firm may be subject; or
  • for compliance with legal obligations and requirements of governmental authorities.

3.8       INTERNATIONAL TRANSFER

The services provided by Pinheiro Guimarães require the support of a technological infrastructure that may, at any time, be established outside Brazil, such as servers and cloud services, which may be owned or provided by third parties. In addition, to render its services, Pinheiro Guimarães may need to share Personal Data with other Personnel or third parties outside Brazil, such as partner law firms or foreign governmental entities, as necessary for the rendering of its services.

Any international transfer of Personal Data will be carried out by Pinheiro Guimarães only in those cases permitted by applicable Law, including for the purposes of complying with: (i) contractual, legal, or regulatory obligations; (ii) global corporate rules, certifications, and codes of conduct that such third parties are committed to observe; and (iii) the terms and conditions set forth in any appropriate Personal Data transfer agreement governing any such international transfer of Personal Data, as applicable, to which Pinheiro Guimarães is a party.

  1. INSTITUTIONAL WEBSITE

4.1       Cookies

Cookies are small files created by websites visited that are stored in the User’s computer and mobile device browsers. These files contain information used to identify the visitor and customize the content of web pages according to the User’s profile and preferences. Additionally, they facilitate data transport between pages of the same website, assess website performance metrics, identify usability issues, enable the proper functioning of the website, and collect behavioral information about the User while navigating the website.

Pinheiro Guimarães uses cookies to improve the functionality of its institutional website, to ensure adequate security and performance, to save User preferences, to provide a personalized browsing experience (for example, language), and to collect behavioral information about Users that may enable continuous improvement of the website’s quality.

4.2       Links to Third-Party Websites

The website of Pinheiro Guimarães may contain links to third-party websites that, as a rule, have their own privacy and data-protection policies. Such policies may not be compatible with this Policy. Moreover, third parties may not adopt the same security measures adopted by Pinheiro Guimarães or required by applicable Legislation.

Pinheiro Guimarães assumes no responsibility for third-party websites or for the existence or adequacy of Personal Data-protection practices on third-party websites. In addition, Pinheiro Guimarães does not assume responsibility for, share, endorse, monitor, validate, accept, or ratify the content of, policies or procedures for Processing of Personal Data by any such third-party website. Moreover, Pinheiro Guimarães assumes no responsibility for any incidents or security breaches that may compromise Users’ Personal Data while any User may be browsing any third-party website.

It is therefore recommended that Users adopt appropriate security measures and follow procedures and precautions when accessing third-party websites. It is further recommended that Users review their own applicable privacy policies for information regarding the Processing of their Personal Data.

  1. DATA SUBJECT RIGHTS

The LGPD and the Federal Constitution guarantee Data Subjects a number of rights, including: (i) confirmation of the existence of Processing of Personal Data; (ii) access to their Personal Data Processed by Pinheiro Guimarães; (iii) correction of incomplete, inaccurate, or outdated data; (iv) anonymization, blocking, or deletion of unnecessary, excessive, or non-compliant data Processed in violation of applicable Legislation; (v) data portability to another service or product provider, upon express request, in accordance with the regulations of the ANPD (Brazil’s National Data Protection Authority), subject to trade and industrial secrets; (vi) request for information regarding Personal Data shared with public and private entities; (vii) request for information regarding the possibility of withholding consent and the consequences of refusal; (viii) deletion of Personal Data Processed on the basis of the Data Subject’s consent; and (ix) revocation of consent for the Processing of Personal Data.

Deletion of Personal Data Processed on the basis of the Data Subject’s consent may be requested at any time. Upon such request, Pinheiro Guimarães will proceed with the deletion of the Personal Data subject to such request, except in the circumstances provided for in the LGPD and applicable Laws that permit or require the continued storage thereof, for example, in the case of compliance with a legal or regulatory obligation or in the case of use of Personal Data in anonymized form.

The Data Subject may revoke their consent for one or more specific types of Processing at any time by means of an express declaration, at no cost and through readily accessible means, it being understood that any Processing previously carried out under the consent then in effect will remain valid.

Data Subject rights may be exercised at any time by submitting a request to Pinheiro Guimarães through the communication channel indicated below. Data Subjects may also file complaints with the ANPD (Brazil’s National Data Protection Authority) regarding any irregularity or breach of their rights described herein.

  1. PROTECTION AND SECURITY

Pinheiro Guimarães adopts protection and security measures based on best market practices to protect Personal Data against unauthorized access, incidents, or unlawful or accidental situations that may cause destruction, loss, alteration, improper disclosure, or any other form of inadequate Processing. Personal Data is stored in a segregated and secure operational environment that is not publicly accessible.

To ensure a high level of protection and security, Pinheiro Guimarães maintains an Information Security Policy detailing the technical and operational measures adopted for the protection and security of Personal Data and IT systems, as well as specific procedures including access control and limitation, network access monitoring, blocking of access to social media and certain websites on corporate devices, monitoring of corporate services and devices, user authentication with periodic password changes, internal training, prevention, detection, and blocking of unauthorized access or security incidents, antivirus, firewall, VPN, database segmentation, logical network segmentation, periodic testing and system scans, traceability mechanisms, maintenance of backup copies, and cloud storage.

All measures are adopted to minimize the risks of security incidents, unauthorized access, and breaches of Personal Data. However, it is not possible to guarantee the absolute security of Personal Data Processed by Pinheiro Guimarães, particularly against cyberattacks using techniques and methods considered innovative, sophisticated, or unknown even to the best information security tools.

Likewise, Data Subjects and Clients should also adopt security measures on their computers and mobile devices. Should the Data Subject or Client identify or become aware of anything that may compromise the security of their Personal Data, or of any possible vulnerability on the website or in the systems of Pinheiro Guimarães, please contact Pinheiro Guimarães through the communication channel indicated below.

  1. COMMUNICATION CHANNEL

Pinheiro Guimarães provides secure and reliable communication channels, encouraging Data Subjects and any third parties acting in good faith to report or request clarification regarding any questions or situations indicating the occurrence of incidents, unauthorized access, or known or potential breaches of information security, Personal Data, or this Policy.

Any report, complaint, or inquiry may be submitted confidentially through the channel below:

Data Protection Officer: Bruno Lardosa

privacidade@pinheiroguimaraes.com.br

+55 (21) 4501.5000

Pinheiro Guimarães shall maintain confidentiality with respect to your identity, except in cases where it is necessary to use the Personal Data for (i) compliance with a legal or regulatory obligation, (ii) research by a research entity, with anonymization of personal data ensured whenever possible, (iii) transfer to a third party, provided that the requirements for Processing of Personal Data are observed, or (iv) exclusive use by Pinheiro Guimarães, with third-party access prohibited, and provided that the Personal Data has been anonymized.

  1. CERTIFICATIONS

Pinheiro Guimarães holds ISO 27001 and ISO 27701 certifications, reaffirming its commitment to information security management and data privacy. These certifications are recognized by the IAF (International Accreditation Forum), the leading global accreditation body, and the firm’s management system has been audited by QMS Certification, a benchmark in auditing and certification, reinforcing Pinheiro Guimarães’ dedication to delivering high-quality and trustworthy services.

  1. AMENDMENTS AND REVISIONS TO THE PRIVACY AND PERSONAL DATA POLICY

This Policy may be amended and updated over time to reflect best practices in the Processing of Personal Data and to provide greater security, protection, and transparency, as rules and regulations are issued by the ANPD (Brazil’s National Data Protection Authority) or as updates to applicable Legislation are enacted.

Accordingly, it is recommended that the most up-to-date version of this Policy be periodically reviewed to identify any amendments at www.pinheiroguimaraes.com.br.