The objective of Data Protection at EGATI ENGENHARIA, TECNOLOGIA E NEGÓCIOS LTDA is to ensure the systematic and effective management of all aspects related to the protection of personal data and the rights of its holders, providing support to the critical operations of the business and minimizing identified risks and their possible impacts on the organization.
The Board of Directors and the Management Committee for the Personal Data Protection are committed to an effective management of the Personal Data Protection at EGATI ENGENHARIA, TECNOLOGIA E NEGÓCIOS LTDA. Therefore, they take all appropriate measures to ensure that this policy is properly communicated, understood and adhered to at all levels of the organization. Periodic revisions will be conducted to ensure its continuous relevance and adequacy to the needs of EGATI ENGENHARIA, TECNOLOGIA e NEGÓCIOS LTDA.
It is the policy of EGATI ENGENHARIA, TECNOLOGIA E NEGÓCIOS LTDA to:
Ensure the data subjects the choice of allowing or not the processing of their personal data, except in cases where the applicable law specifically allows the personal data processing without the data subject consent;
Ensure that the personal data processing purpose complies with current legislation and with the applicable legal basis;
Clearly and adequately communicate the personal data processing to the data subject before the data is collected or used for the first time for a new purpose;
Where necessary, provide the data subject with sufficient explanations about his/her personal data processing, as provided for in current legislation;
Limit the personal data collection strictly to what is allowed according to current legislation, and the objectives specified in the data subject consent for the personal data collection, minimizing, whenever possible, the collection of said personal data.
Limit the use, storage, disclosure and transfer of personal data to the strictly necessary to meet specific, explicit and legitimate objectives;
Storage personal data only for as long as necessary to fulfill the stated purposes and subsequently delete, block or anonymize them safely;
Block access to personal data and further processing when the stated purposes expire, except when personal data storage is required by current law.
Ensure the accuracy and quality of processed personal data, except in cases where there is a legal basis for keeping data out of date.
Provide the data subjects with the data processed, clear and easily accessible information about the policies, procedures and practices regarding the personal data processing developed by the organization, including what data is actually processed, the purpose of such processing, and information on how to contact us for further details.
Notify data subjects when significant changes occur in the processing of their personal data.
Ensure that data subjects have the possibility to access and review their personal data, provided that their identity is authenticated with an appropriate level of guarantee, and that there is no legal restriction to such access or review of personal data.
Ensure traceability and accountability throughout the personal data processing, including when personal data is shared with third parties.
Fully address data breaches, ensuring that they are properly recorded, classified, investigated, remedied and documented.
Ensure that, in the event of a data breach, all interested parties are notified according to the requirements and deadlines provided for in the legislation in force.
Document and communicate, as appropriate, all policies, procedures and practices related to privacy and data protection.
Ensure the existence of a person responsible for documenting, implementing and communicating policies, procedures and practices related to privacy and data protection;
Adopt information security controls, both technical and administrative, sufficient to ensure adequate levels of protection for Personal Data.
Provide policies, standards and procedures for the personal data protection to all interested and authorized parties, such as: employees, contracted third parties and, when applicable, customers.
Ensure the education and awareness of employees, contracted third parties and, when applicable, partners and customers, about the personal data protection practices adopted by EGATI ENGENHARIA, TECNOLOGIA E NEGÓCIOS LTDA.
Continuously improve Personal Data Protection Management by systematically defining and reviewing privacy and personal data protection objectives at all levels of the organization.
Ensure the non-discrimination in the personal data processing, making their use impossible for discriminatory, unlawful or abusive purposes.
Ensure the full compliance with personal data protection laws and regulations.