Privacy Policy

1. PURPOSE

This Privacy Policy aims to demonstrate Algar Tech’s (Algar Tecnologia e Consultoria
S/A) commitment to protecting privacy and personal data in the processing activities
carried out by the organization in its processes, systems, and services. It establishes
the rules regarding the collection, recording, storage, use, sharing, enrichment, and
deletion of collected data, in accordance with current legislation. This policy applies to all personal data subjects whose information is processed by Algar Tech, namely: Job
Candidates, Associates, Clients, Suppliers, Partners, and Visitors.

2. Description

2.1. PROCESSING OF PERSONAL DATA

2.1.1. In the general context of the services provided by Algar Tech, personal data may
be processed for the purposes listed below, always respecting and observing the
principles established in the General Data Protection Law (“LGPD”):

  • Sell a product or service, collect debts, resolve inquiries, refer technical
    support, or handle various customer requests, including those of customers of
    its clients or potential customers of its clients;
  • Solve issues related to information security within Algar Tech’s environment;
  • Access information about team members for the purpose of evaluating data and
    managing the team;
  • Recruit and select potential associates, or discard résumés;
  • Approve vacation, travel, and purchase requests;
  • Obtain various reports;
  • Control physical access to Algar Tech’s premises, as well as monitor this access
    through an internal biometric and security camera system;
  • Record service calls made by associates to Algar Tech’s clients;
  • Create user accounts within Algar Tech’s network environment;
  • Update department indicators;
  • Manage SLA indicators;
  • Conduct internal investigations;
  • Generate performance reports;
  • Generate leads;
  • Improve and increase the efficiency of the services provided;
  • Analyze bids, RFIs, RFQs, and RFPs;
  • Update registration data;
  • Prospect new clients;
  • Manage Judicial, Extrajudicial, Arbitral, and Administrative Proceedings;
  • Execute contracts and legal instruments;
  • Hire suppliers and partners;
  • Respond to judicial and extrajudicial summonses and notifications.

These purposes are justified by contractual, legal, or Algar Tech’s legitimate interests.

2.2. 2.2 DATA COLLECTED, PURPOSE OF COLLECTION AND LEGAL BASIS

Data is collected through various processing activities carried out by Algar Tech in its
systems and services. Personal data such as name, CPF (Individual Taxpayer Registry),
RG (General Registry), email, address, phone number, username, banking information,
employment contract data, vehicle information, job title/profession, education,
photograph, biometrics, among others, may be collected, always for a specific purpose
and with proper legal justification, in accordance with current legislation.

A detailed table containing the types of data processed, their purposes, and legal bases
can be requested via the following email: dataprivacy@algartech.com

2.3. 2.3 RETENTION PERIOD OF PERSONAL DATA

2.3.1. 2.3.1. STORAGE

2.3.1.1. Personal data will be retained for the period necessary to fulfill the purposes of
the processing and/or to comply with legal obligations. Thus, whenever applicable, unnecessary or excessive personal data will be deleted, anonymized, or removed upon express request by the data subject or by the National Authority. Information required to comply with legal and regulatory obligations or to exercise rights in administrative,
judicial, or arbitral proceedings will be preserved.

2.3.1.2. Physical storage of personal data

The physical storage of personal data described in this item 2.3 shall also comply with
the timeframes mentioned herein for proper disposal.

2.4. 2.4. DATA DELETION

Data may be deleted before the periods established above if requested by the data
subject. However, it is possible that the data may need to be retained for a longer
period, in accordance with Article 16 of the General Data Protection Law, to comply
with legal or regulatory obligations, to fulfill a contract, or for transfer to a third party (in
compliance with the data processing requirements set forth in the same law). Once the
legal period and necessity expire, the data will be deleted using secure disposal
methods or anonymized for statistical purposes. Once the legal period and necessity expire, the data will be deleted using secure disposal
methods or anonymized for statistical purposes.

2.5. DATA SECURITY

Algar Tech commits to making its best efforts to protect information—especially
personal data—by applying and adopting the necessary administrative and technical
protection measures and establishing good governance practices through the
resources available at the time. It also requires the same acceptable level of
Information Security from its suppliers and clients, based on market best practices,
through contractual clauses.

2.6. STORAGE SERVERS

The collected data will be stored on Algar Tech’s own servers located in Brazil, as well
as in environments using cloud computing resources or servers. In the latter case, data
transfer or processing outside Brazil may occur, in compliance with international data
transfer provisions as established in Article 33 of the General Data Protection Law or
other applicable regulations.

2.7. ACCURACY OF DATA

2.7.1. 2.7.1. Algar Tech is not responsible for the accuracy, truthfulness, or lack thereof in the
information provided by the personal data subject, nor for outdated information or
documents submitted, as the responsibility for providing accurate and/or updated data
lies with the individual supplying it.

2.7.2. 2.7.2. Algar Tech is not obliged to process or handle any data if there are reasons to
believe that such processing may result in violations of any applicable law, or if
intended for illegal, unlawful, or immoral purposes.

2.8. RIGHTS OF THE PERSONAL DATA SUBJECT

2.8.1. 2.8.1. It is the responsibility of the data collector to ensure that the Data Subject can
exercise their rights over the collected data.

2.8.2. 2.8.2. The Data Subject has the right to request confirmation that their data is being
processed, to request access to their data, to correct data that is incorrect,
incomplete, or outdated, to request anonymization, blocking, or deletion of
unnecessary or excessive data, to request data portability, and to request the deletion
of their personal data. They also have the right to know with whom their data has been
shared, to receive information about the consequences of refusing to give consent, and
to withdraw previously given consent at any time.

2.8.3. Any request must be made by express demand of the data subject or their legally
appointed representative. In such cases, if there is any request, complaint, or
questions regarding their personal data, the data subject or their representative should
contact Algar Tech’s DPO directly via the email: dataprivacy@algartech.com.

2.8.4. 2.8.4. Additionally, under any circumstances, the personal data subject has the right to
file a complaint with the competent data protection authority.

2.9. DATA SHARING WITH THIRD PARTIES

2.9.1. 2.9.1. Corporate instruments, powers of attorney, and copies of personal documents of
ALGAR TECH’s legal representatives may be shared by email with associates, clients,
and suppliers, as a means of verifying the authenticity of identification and qualification
information.

2.9.2. Physical and digitized copies of documents related to judicial, extrajudicial, and
administrative subpoenas and notifications may be requested by Algar CSC or a third-
party law firm handling a legal or extrajudicial matter. These documents may be shared
with law firms and outsourced experts for the purpose of supporting the respective
proceedings.

2.9.3. 2.9.3. Personal documents and documents of legal representatives necessary for the
preparation of legal instruments may be shared, including in cases involving updates to
corporate documents before third parties, such as external attorneys and accountants.

2.9.4. The Legal Department uses reports generated by ALGAR CSC or third-party firms
to manage accounting provisions required by ALGAR TECH’s accounting team.
Therefore, personal data contained in such reports is shared with ALGAR CSC’s
accounting department or with the third-party firm managing ALGAR TECH’s
accounting.

2.9.5. Since the CX department works with its clients’ databases, it operates with data
sets shared by these clients. These datasets involve a large number of data subjects
and personal data, many of which are processed automatically or enriched by ALGAR
TECH suppliers.

2.9.6. 2.9.6. Personal documents and data of associates may be shared with ALGAR TECH
clients when necessary for the execution of a contract or preliminary procedures
related to a contract. If data is shared through portals made available by clients and/or
suppliers, the Information Security department must evaluate it via a support ticket
registered in the current service management tool.

2.9.7. 2.9.7. Personal data may be shared with Public Authorities or government entities that
legally require ALGAR TECH to provide specific Personal Data, for example, during an
investigation, unless ALGAR TECH deems the request an abuse of power.

2.9.8. Personal data may be shared with partner companies and suppliers for the
development of activities and service provision, provided such sharing is duly
supported by contractual agreements.

2.10. INTERNATIONAL TRANSFER

Personal data may be transferred to other countries (international transfer) in projects
involving cloud services, to the extent that the service provider’s servers—AWS—are
located in the United States of America and Europe. This requires the contractual
agreement with the provider to be properly adjusted to ensure compliance with Chapter
V of the General Data Protection Law (LGPD).

2.11. 2.11. EMAIL MARKETING AND CONSENT WITHDRAWAL

2.11.1. 2.11.1. The RD Station tool is used to automate Marketing actions after lead generation,
managing the sending of marketing emails to individuals listed in the mailing list.

2.11.2. Its configuration is shared between ALGAR TECH and the solution provider
when the Marketing team itself sends the emails, as requested by the department. All
marketing emails allow the data subject to opt out of receiving them, and they are
promptly removed from the active list. Data will be discarded upon the data subject’s
request or according to the timelines set in the Retention Schedule.

2.11.3. 2.11.3. The data subject has the right to withdraw previously granted consent for
receiving marketing emails at any time.

2.12. AUTOMATED DECISIONS

2.12.1. 2.12.1. In relation to security solutions at Algar Tech, detections may be automated
through monitoring software internally implemented.

2.12.2. 2.12.2. Personal data necessary for user creation in Active Directory is accessed
automatically through the integration of internal solutions.

2.12.3. The RD Station tool automates the actions of the Marketing department, as
described in item 2.10.

2.13. MINORS’ DATA

2.13.1. 2.13.1. Employment contracts for associates must contain specific provisions for
underage dependents, as parental or legal guardian consent is required for processing
minors’ personal data.

2.13.2. 2.13.2. The same applies to the visitation of minors to Algar Tech facilities, during which
their legal guardian must sign a consent form authorizing the collection and processing
of the minor’s data.

2.14. SENSITIVE DATA

2.14.1. ALGAR TECH may occasionally collect sensitive data relating to racial or ethnic origin,
political opinions, trade union membership, health or life-related data, genetic or
biometric data. The processing of such data strictly follows applicable legal provisions,
always adhering to the purpose of processing and respecting the necessary legal
bases. Personal data and other information are anonymized through encryption and
restricted access control.

2.15. INCIDENT NOTIFICATION

2.15.1. 2.15.1. If ALGAR TECH identifies or becomes aware of any breach or incident resulting
in destruction, loss, alteration, disclosure, or unauthorized access during the
processing of data that may pose potential risk to the data subject, the company
commits to investigating the incident, notifying the data subject within the legally
specified timeframe, and taking reasonable measures to mitigate or minimize any
resulting damages from the incident and/or breach.

2.15.2. 2.15.2. Incident notifications will be delivered to the data subject through any means
selected by ALGAR TECH, including electronic means; therefore, it is the sole
responsibility of the data subject to ensure that ALGAR TECH has accurate contact
information.

2.15.3. 2.15.3. The data subject—whether an associate, supplier, client, or otherwise—who
becomes aware of any possible misuse, incident, or breach involving their data related
to services involving ALGAR TECH must notify the company immediately.

2.16. APPLICABLE LAW AND JURISDICTION

This Privacy Policy shall be governed by and interpreted in accordance with Brazilian
law, in the Portuguese language.

2.17. 2.17. COMMUNICATION

The data subject acknowledges that all communications carried out via email to the
addresses provided in their registration, SMS (short message service), instant
messaging apps, or any other digital and virtual means shall also be considered valid as
documentary evidence. Such communications are effective and sufficient for
conveying any matter related to services provided by ALGAR TECH, including the
conditions of service provision or any other matter addressed therein, except as
otherwise provided in this Policy.

Any questions or requests may be directed to the Data Protection Officer (DPO), Mr.
Carlos Eduardo Lopes, via email at: dataprivacy@algartech.com.

3. GENERAL PROVISIONS

Algar Tech reserves the right to modify the content of this Policy at any time, as
necessary or appropriate, including to ensure legal compliance with applicable laws or
regulations having equivalent legal force. It is the responsibility of the data subject to
review this Policy periodically through the Algar Tech website at:
https://algartech.com/.

1
Solution
2
About you
3
About your business
Please select one of the options.
Your full name.
Your work email.
Your work phone number. Use numbers only.
Your mobile phone number. Use numbers only.
Por favor, preencha todos os campos do formulário.