bg shape

Privacy and Security Policy

1. Objective and Scope

The purpose of this Privacy and Data Protection Policy (Privacy Policy) is to demonstrate the commitment of Telecontrol Networking or any other company that may join the group to privacy and data protection, bringing transparency and clarity to the relationships that Telecontrol has with data subjects.

2. Guidelines

As a condition for accessing and using the Telecontrol system features, the user declares that he/she has read this Privacy Policy in full and carefully, and is fully aware that, by accessing the features of Telecontrol websites and platforms and/or by providing his/her personal data, he/she will be giving, thus, his/her free and express agreement with the terms stipulated herein. IF YOU DO NOT AGREE WITH THIS POLICY, PLEASE DISCONTINUE YOUR ACCESS TO ANY TELECONTROL APPLICATION OR WEBSITE AND DO NOT PROVIDE YOUR DATA.

3. Generation, Collection and Use of Data and Activity Recording

  • 3.1. The data generated by TELECONTROL, collected from voluntary submission by the user or collected automatically through electronic records, comply with the principles of purpose, necessity, adequacy, transparency and non-discrimination under the terms of laws and regulations.
  • 3.2. TELECONTROL only collects information directly from the user through its own forms that are filled out and validated by it through the electronic means made available.
  • 3.3. When the user browses digital platforms or uses products or services that are made available via the internet, TELECONTROL collects data from its users.
  • 3.4. When using database suppliers, TELECONTROL chooses reputable companies that respect privacy and data protection rules, in addition to requiring that they comply with data processing rules established by it.
  • 3.5. All data collected may be used as evidence in cases of unlawful acts or acts contrary to this Policy or any other legal document made available by TELECONTROL, as well as to comply with a court order or administrative request or to protect rights.
  • 3.5.1. When accessing applications and its website, TELECONTROL collects cookies that serve to facilitate and improve navigation on its website and application. The user can configure his/her device, if he/she wishes to block the collection of cookies or other data, but in this case, some TELECONTROL functionalities may be limited.
  • 3.6. TELECONTROL is not responsible for the accuracy, veracity or lack of data and information provided by the user or for their outdatedness. It is the user's responsibility to declare their data and information accurately and update them whenever necessary, using the service channels dedicated to this purpose, which are disclosed on the Privacy Portal.
  • 3.7. The database created through data collection in TELECONTROL is the property and responsibility of TELECONTROL, and its use, access and sharing, when necessary, will be done within the limits and purposes of TELECONTROL's business and described in this Privacy Policy or Complementary Privacy Policies, and also in compliance with its Cybersecurity Policy.
  • 3.7.1. The user is jointly responsible for the confidentiality of his/her data. Sharing passwords and access data violates this TELECONTROL Privacy Policy.
  • 3.8. Internally, user data will only be accessed by professionals duly authorized by TELECONTROL, respecting the principles of proportionality and necessity, as well as the purpose for TELECONTROL's objectives, in addition to the commitment to confidentiality and preservation of privacy under the terms of this Privacy Policy.

4. Storage, International Transfer, Retention and Deletion of Data

  • 4.1. The data processed by TELECONTROL is stored in the United States of America, on servers contracted by and under the responsibility of TELECONTROL.
  • 4.1.1. Depending on the Product or Service, in order to operate efficiently and improve performance, TELECONTROL may carry out international transfers of its customers’ data. In this case, TELECONTROL takes the necessary measures to ensure that the information processed internationally complies with this Policy and also with other data processing and security policies and procedures of TELECONTROL, since these are based on the laws and regulations governing data protection and privacy in Brazil and also on the best information security practices in the market. Information regarding the region, countries, processing agents and purposes will be indicated in the Terms of Use or in specific Contracts related to the products or services contracted, in a clause identified as “Privacy Policy”.
  • 4.2. For auditing, security, fraud control, preservation of rights and compliance with legal obligations, TELECONTROL may retain personal data for the duration of its intended use or legal, regulatory or judicial obligation that justifies its retention. At the end of the intended use and the mandatory retention period, the data will be deleted using secure disposal methods or anonymized for use for statistical purposes.
  • 4.2.1. If the user requests the deletion of data, this deletion may only occur if there is no longer any purpose for its use or legal, regulatory or judicial obligation that justifies its retention.
  • 4.2.2. In operations carried out via the internet, the user access log history will be collected and stored for a period of up to 6 (six) months, in accordance with the legal provisions of the Internet Civil Rights Framework (Law No. 12,965/2014), and in the event that storage is necessary to preserve rights, the maximum period will be 10 (ten) years, in accordance with the Brazilian Civil Code (Federal Law 10,406/2002).

5. Sharing

  • 5.1. The data collected and the activities recorded may be shared:
    • i) With competent judicial, administrative or governmental authorities, whenever there is a legal request from the authorities or a court order or for the regular exercise of a right, execution of a contract or for compliance with a legal or regulatory obligation;
    • ii) In the event of corporate transactions, such as mergers, acquisitions or incorporations, or in the event of assignment of rights;
    • iii) With the service providers contracted by TELECONTROL to make the TELECONTROL website and platform viable together with all its functionalities and services made available;
    • iv) Automatically, with service providers or partners to support the performance of TELECONTROL activities, such as Call Center, Product and Service Marketing, Technical Infrastructure Operation, Law Firms;
    • v) With third parties, to display advertisements to users in online advertising on their own or third-party websites, sending electronic messages, telephone calls or even direct mail by post;
    • vi) With third parties to execute contracts formalized with the user.
  • 5.2. All third parties (service providers and partners) contracted by TELECONTROL and who process user data are obliged to carry out processing operations confidentially and only for the contracted purpose, ensuring legal compliance with regard to privacy and data protection and, at all times, using the best information security practices and with the same guarantees established in this Policy and in TELECONTROL's Information Security Policy.

6. Consent

When the use of data is based on the consent of the holder, this will be collected from the user in a free, informed, highlighted, specific and legitimate manner.

7. Access, Rectification, Portability, Limitation, Opposition and Deletion of Data

  • 7.1 TELECONTROL makes available to its users, on the internet, a Privacy Portal where it makes available its privacy and protection policies.
    • 7.2. Through the service channel, the user can request information about their data.
    • 7.3. TELECONTROL uses systematically parameterized decisions for the user's contracting of products and services, considering criteria established in its specific internal policies for each product or service made available, in a non-discriminatory manner, respecting sectoral and general laws and regulations governing privacy and data protection, and strictly following the standards published by regulators.
    • 7.3.1. The user may exercise his/her right to review automated decisions through the Service Channels available on the TELECONTROL Privacy Portal.

    8. Security and Incidents

    • 8.1. TELECONTROL processes data in accordance with best security practices, adopting physical, administrative and logical measures proportional to the sensitivity, volume, format and processing methods used to protect information against loss, improper use and access, unauthorized disclosure, alteration and destruction.
    • 8.2. All data collected is stored in a secure environment and in compliance with TELECONTROL's Information Security Policy. The security measures adopted are periodically tested to ensure the privacy and protection of users' data. However, there is a certain level of risk when collecting, processing and storing information since no security system is infallible, and for this reason TELECONTROL is exempt from any liability for any damages and/or losses resulting from failures, viruses or invasions of TELECONTROL's database.
    • 8.3. In the event of a security incident involving collected data, TELECONTROL will handle the situation in accordance with its Incident Management Policy, which has procedures and analysis techniques, including the legal and permitted use of forensic data, which help areas identify, monitor, report and resolve data breach incidents and categorize their criticality.
    • 8.4. Any data breach incident (data incident), as is the case with security incidents, will be recorded by TELECONTROL and handled by its Information Security team. If, eventually, the data incident poses a significant risk to the user's privacy and freedom, the user will be notified of the occurrence, preferably by electronic message and via the email registered with TELECONTROL.
    • 8.5. The notification referred to in the previous item will contain, at a minimum, information that allows the recipient to identify the violated data, the risks of this violation, the technical and operational measures taken to mitigate the risks of the incident, among other information required by law or specific regulation, in addition to that which TELECONTROL deems important to report the occurrence and the measures that are being taken to mitigate the risks of the holder.

    9. General Provisions

    • 9.1. TELECONTROL may establish in a separate instrument an additional and specific Privacy Policy for certain products or services, when necessary. This information will be included in the contracts or Terms of Use of the Product or Service in a specific clause identified as “Privacy Policy”.
    • 9.2. TELECONTROL reserves the right to change the content of this Privacy Policy at any time, depending on the purpose or need, such as for adequacy and compliance with the law or regulation that has equivalent legal force.
    • 9.2.1. The user must read the new version of the Privacy Policy when notified, to assess whether he/she agrees with the changes made, and whether he/she wishes to continue using and accessing TELECONTROL's services and products.
    • 9.3. TELECONTROL acknowledges that depending on the jurisdiction where the business relationship is formalized and/or operated with the user, local data protection and privacy legislation will apply. For this reason, the Policies and rules governing data protection and privacy of the jurisdictions where TELECONTROL may formalize operations and transactions with users will be available on the Privacy Portal.
    • 9.4. If any provision of this Privacy Policy is considered illegal or illegitimate by the competent authority of the location in which the user is located, the remaining conditions will remain in full force and effect.
    • 9.5. The user acknowledges that all communication made by email, SMS, instant messaging applications or any other electronic form is also valid as documentary evidence, being effective and sufficient for the disclosure of any matter relating to the services provided by TELECONTROL, as well as the conditions of their provision or any other matter addressed therein, except for the expressly different provisions set forth in this Privacy Policy.

    10. Data Processing Officer, Privacy Policy and Data Protection

  • 10.1 If the user finds that any provision of this policy or other related provisions is not being observed or that there is any provision that is not in accordance with the provisions of the legislation that regulates privacy and data protection, or if there is any doubt regarding the provisions of this Policy and any other document that deals with your Privacy in the relationships established with TELECONTROL, please contact our Data Protection Department and speak to our legal department via email at juridico@telecontrol.com.br. Responses to contact will be sent between Monday and Friday (except holidays), during business hours.
  • 11. Glossary

    For the purposes of this document, the following definitions and descriptions should be considered for better understanding:

    • Database: structured set of personal data, established in one or more locations, in electronic or physical support.
    • Cookies: small files temporarily stored on the user's computer, used to identify browsing preferences and other information related to your visit to a specific website/web page.
    • Data: information that identifies or makes a user identifiable.
    • IP:Abbreviation for Internet Protocol. It is a numerical sequence that identifies connections and/or devices (such as computers, tablets and smartphones) of users on the Internet.
    • Data Processing: any and all operations carried out with collected data, such as those related to: collection, production, reception, classification, use, access, reproduction, transmission, distribution, processing, archiving, storage, elimination, evaluation or control of information, modification, communication, transfer, dissemination or extraction.
    • User: Any legal entity or individual that accesses and/or uses TELECONTROL’s features and/or services.
    • International Data Transfer: occurs when data is sent to another country.
    • Data Breach: security incident that causes, accidentally or unlawfully, the destruction, loss, alteration, disclosure or unauthorized access to collected data.
    • Consent: free, informed and unequivocal expression by which the holder agrees to the processing of his/her data for a specific purpose.
    • Anonymization: use of reasonable technical means available at the time of processing, through which data loses the possibility of association, directly or indirectly, with a user.
    • Elimination: deletion of data or a set of data stored in a database, regardless of the procedure used.

    12. Applicable Law and Jurisdiction

  • 12.1 This document shall be governed by and construed in accordance with Brazilian law, in the Portuguese language, and the TELECONTROL forum shall be elected to settle any dispute or controversy involving this document, unless there is a specific reservation regarding personal, territorial or functional jurisdiction under applicable law.
  • 13. Applicable Regulations

  • 13.1 This document was prepared based on the laws and regulations that govern privacy and data protection, such as: Brazilian Federal Constitution Brazilian Civil Code (Federal Law No. 10,406/2002) Consumer Protection Code (Federal Law 10,820/1990) Internet Civil Rights Framework (Law No. 12,965/2014), Access to Information Law (Law No. 12,527/2011), Cybersecurity (CMN Resolution No. 4,658/2018).

  • Thank you for your attention, and welcome to TELECONTROL!