We at WeCheck d/b/a WeCheck (“WeCheck“, “us”, “we“, or “our“) recognize and respect the importance of maintaining the privacy of our Customers and their Personnel. This Privacy Notice describes the types of information we collect from you when you visit our website (“Site“) and/or use our Platform, Apps, and/or Services. This Privacy Notice also explains how we collect, process, transfer, store and disclose the information collected, as well as your ability to control certain uses of the collected information. If not otherwise defined herein, capitalizedterms have the meaning given to them in the Terms of Service, available at https://www.WeCheck.com.br (“Terms“). “You” means any adult user of the Site, App, Platform and/or Services. When we process information in the context of providing Services to our Customers, including with regard to each Customer’s Personnel, the applicable Customer serves as a controller with respect to Personal Data (as defined below) of its Personnel.

WeCheck is a data controller in respect of the processing activities outlined in this Privacy Notice that relate to our Customers and visitors to the Site. WeCheck’s registered office is Avenida Rouxinol, 1041, conjunto 103, Indianópolis, 04516-001 – São Paulo. For further details regarding our arrangement with WeCheck, please contact us at contato@WeCheck.com.br

“Personal Data” means any information that refers, is related to, or is associated with an identified or identifiable individual or as otherwise may be defined by applicable law. This Privacy Notice details which Personal Data is collected by us in connection with provision of the Site and Services.

Privacy Notice Key Points

The key points listed below are presented in further detail throughout this Privacy Notice. You can click on any section in order to find out more information about any topic.

• Personal Data We Collect, Uses and Legal Basis. The types of Personal Data we collect, the way in which we use it, and the legal basis on which we do so will depending on the type of account you have and your usage of our Site and Services. For example, if you have a registered account on the Platform, we will collect Personal Data you provide such as registration data and contact information. When you visit the Site or use the Services, we also collect certain Personal Data automatically. We use your Personal Data for various reasons, including to provide you with the Site, Platform, Apps, and Services improve our Services, and to contact you with marketing offers from WeCheck only, such as announcements and promotions of new features and product capabilities. These processing activities are based on different legal bases including performance of a contract, legitimate interests, and your consent.

• Sharing the Personal Data We Collect. We share the Personal Data we collect with our service providers and subcontractors who assist us in the operation of the Site, Platform, and Apps and process the information on our behalf and under our instructions, as well as with WeCheck, which serves as a joint controller of the data. When we act as a processor on behalf of our Customers, we will share your Personal Data with the applicable Customer

• Security . We implement measures aimed at protecting your Personal Data, but they do not provide  absolute information security. Such measures include physical, electronic, and procedural safeguards (such as secure servers, DDOS protection, firewalls, antivirus and SSL encryption), access control, and  other internal security policies

• Your Rights. Subject to applicable law and in addition to other rights as set forth below, you may have a right to access, update, delete, and/or obtain a copy of the Personal Data we have collected about you. You also have the right to object at any time to processing your Personal Data for certain purposes, including marketing purposes.

Data Retention. We retain Personal Data for as long as necessary for the purposes set forth in this Privacy Notice. We consider a number of different factors when determining the appropriate retention periods.

• Children. We do not knowingly collect Personal Data from children under the age of sixteen (16).

• Third-Party Applications and Services. All use of third-party applications or services is at your own risk and subject to such third party’s privacy policies.

• Communications. We may send you e-mail or other messages about us or our Services. You will have the opportunity to opt-out of receiving certain messages that are not service-related.

• Changes to the Privacy Notice. We may change this Privacy Notice from time to time and shall notify you of such changes by indicating on the Site that the Privacy Notice has been amended by publishing an updated Privacy Notice on the Site.

• Comments and Questions. We have appointed a data protection officer (“DPO”) who is responsible for  overseeing our privacy practices. If you have any comments or questions about this Privacy Notice, or if you wish to exercise your legal rights with respect to your Personal Data, please contact our DPO at contato@WeCheck.com.br

Personal Data We Collect, Uses and Legal Basis

Depending on your usage, we collect different types of data and we and any of our third-party subcontractors and service providers use the data we collect for different purposes, as specified below. It is your voluntary decision whether to provide us with certain Personal Data, but if you refuse to provide such Personal Data we may not be able to register you to the Platform or Apps and/or provide you with the Services or part thereof.

Site Visitors
If you are a visitor to the Site, we collect the following types of Personal Data from you:

• Comments and Questions. We have appointed a data protection officer (“DPO”) who is responsible for  overseeing our privacy practices. If you have any comments or questions about this Privacy Notice, or if you wish to exercise your legal rights with respect to your Personal Data, please contact our DPO at contato@WeCheck.com.br

Contact Information

  • What Personal Data We Collect: When you request information from us through the Site, fill out (online) forms, or contact us for any other reason, we will collect any data you provide, such as your name and/or email address, and the content of your inquiry.
  • How we use this data: To respond to your request or inquiry, to provide you with
    updates on information related to WeCheck, such as newsletters or service releases and for retargeting purposes
  • • Legal Basis: We process this Personal Data based on performance of a contract when
    we respond to your inquiry and provide you with newsletters. Processing your Personal Data for retargeting purposes is based on our legitimate interests.

Automatically Collected Data

  • What Personal Data We Collect: When you visit the Site, we automatically collect information about your computer or mobile device, including non-Personal Data such as your operating system and browser type, internet service provider (ISP), and Personal Data such as your IP address, browsing history, including referring and exit pages, and any information regarding your viewing history on our Site. For more information about the cookies and similar technologies we use and how to adjust your preferences on the Site, please see the section “Cookies and Similar Technologies” below.
  • How we use this data: (1) to review usage and operations, including in an aggregated non-specific analytical manner, develop new products or services and improve current content, products, and services; (2) to prevent fraud, protect the security of our Site and address any problems with the Site; (3) to provide you with customized content, targeted offers, and advertising related to our products and services, based on your usage history on the Site on other third-party sites or apps you may visit and/or use, or via e-mail.
  • Legal Basis: We process this Personal Data for our legitimate interests to develop our products and Services, review usage, perform analytics, prevent fraud, for our recordkeeping and protection of our legal rights and to market our own products and services. Additional information regarding direct marketing is provided below.

Account Owners

If you are an Account Owner using the Platform and/or an App on behalf of a Customer, we collect the following types of Personal Data from you:

Registration Data

  •  What Personal Data We Collect: In order to register to use our Platform, Apps, and/or receive the Services, you will be required to register and to provide all Personal Data requested by us, which includes your full name, email address, and phone number.
  • How we use this data: (1) to provide you with the Platform, Apps, and/or Services and to respond to your inquiries and requests and to contact and communicate with you;
    (2) to prevent fraud, protect the security of and address any problems with the Platform, Apps, and/or Services; and (3) to provide you with informational newsletters and promotional materials relating to our Platform, Apps, and/or Services, including via email. For more information about our direct marketing activities and how you can control your preferences, please see the Direct Marketing section below.
  • Legal Basis: (1) We process this Personal Data for the purpose of providing the Services to you, which is considered performance of a contract with you, including responding to your inquiries and requests and providing customer support; (2) when we process your Personal Data for the purposes of preventing fraud, protecting the security of and/or addressing problems with the Platform, Apps, and/or Services and/or for the purpose of providing you with informational newsletters and promotional materials relating to our Services, such processing is based on our legitimate interests.

Automatically Collected Data

  • What Personal Data We Collect: When you use the Platform or App, we automatically collect information about your computer or mobile device, including non-Personal Data such as your operating system and browser type, internet service provider (ISP), and Personal Data such as your IP address, browsing history, including referring and exit pages, and any information regarding your viewing history on the Platform or App, browser language, and browser time zone. For more information about the cookies and similar technologies we use and how to adjust your preferences on the Platform or App, please see the section “Cookies and Similar Technologies” below.
  • How we use this data: (1) to review usage and operations, including in an aggregated non-specific analytical manner, develop new products or services and improve current content, products, and services; (2) to prevent fraud, protect the security of our Platform and address any problems with the Platform; (3) to provide you with customized content, targeted offers, and advertising related to our products and services, based on your usage history on the Platform or App on other third-party sites or apps you may visit and/or use, or via e-mail.
  • Legal Basis: We process this Personal Data for our legitimate interests to develop our products and Services, review usage, perform analytics, prevent fraud, for our recordkeeping and protection of our legal rights and to market our own products and services. Additional information regarding direct marketing is provided below

Materials You Upload

  • What Personal Data We Collect: Any materials including images and/or pictures and/or photos and/or documents you may upload to the Platform will be collected by us.
  • How we use this data: To provide you with the Services.
  • Legal Basis: We process this Personal Data for the purpose of performance of a contract with you.

Administrators and Employees

If you are an Administrator or an Employee who is using the Platform, Apps, and/or Services, we collect and process the following types of your Personal Data as a processor, all on behalf of and at the direction of the relevant Customer:

Registration Data

  • What Personal Data We Collect: We collect any registration data provided by you or about you, including your full name and phone number as well as email address and job title or any other information requested by the Customer.
  • How we use this data: (1) to provide you and the relevant Customer with the Platform,
    Apps, and/or Services and to respond to your inquiries and requests and to contact and communicate with you and (2) to prevent fraud, protect the security of and address any problems with the Platform, Apps, and/or Services.
  • Legal Basis: We process this Personal Data on behalf of and for the purpose of providing the Services to the relevant Customer, which is considered performance of a contract with that Customer.

Automatically Collected Data

  • What Personal Data We Collect: When you use the Platform or App, we automatically collect information about your computer or mobile device, including non-Personal Data such as your  operating system, device type, and browser type, internet service provider (ISP), and Personal Data such as your IP address, browsing history, including referring and exit pages, information regarding your viewing history on the Platform or App, language, and time zone. For more information about the cookies and similar technologies we use and how to adjust your preferences on the Platform or App, please see the section “Cookies and Similar Technologies” below.
  • How we use this data: To allow the Customer to review usage and operations, including in an aggregated non-specific analytical manner
  • Legal Basis: We process this Personal Data on behalf of and for the purpose of providing the Services to the relevant Customer, which is considered performance of a contract with that Customer

Materials You Upload

  • What Personal Data We Collect: Any materials including images and/or pictures and/or photos and/or documents you may upload to the Platform will be collected by us.
  • How we use this data: To provide the Services.
  • Legal Basis: We process this Personal Data on behalf of and for the purpose of providing the Services to the relevant Customer, which is considered performance of a contract with that Customer.

Geo-location

  • What Personal Data We Collect: Subject to your consent, when you use the Platform, Apps, and/or Services, we collect your (geo)location.
  • How we use this data: We use this information in order to provide location-based Services through the App.
  • Legal Basis: We process this Personal Data based on your consent. You may withdraw your consent at any point by adjusting your device settings.

Sharing the Personal Data We Collect

We share your information, including Personal Data, as follows:

Affiliates

We share information, including your Personal Data, with our wholly owned subsidiary, WeCheck, which serves as a joint controller of such data, for the purpose of providing you with our products and Services and for the management of our business. For further details regarding our arrangement with WeCheck, please contact us at contato@WeCheck.com.br

Service Providers, and Subcontractors

We also disclose information, including Personal Data we collect from and/or about you, to our trusted service providers and subcontractors, who have agreed to confidentiality restrictions and who use such information solely on our behalf in order to: (1) help us provide you with the Platform, Apps, and/or Services; (2) aid in their understanding of how users are using our Platform, Apps, and/or Services; and (3) for the purpose of direct marketing (see above for more details). Such service providers and subcontractors provide us with IT and system administration services, data backup, security, and storage services, data analysis, payment processing, and assist us in our marketing activities.

Business Transfers

Your Personal Data may be disclosed as part of, or during negotiations of, any merger, sale of company assets or acquisition (including in cases of liquidation) in such case, your Personal Data shall continue being subject to the provisions of this Privacy Notice.

Law Enforcement Related Disclosure

We may share your Personal Data with third parties: (i) if we believe in good faith that disclosure is appropriate to protect our or a third party’s rights, property or safety (including the enforcement of the Terms and this Privacy Notice); (ii) when required by law, regulation subpoena, court order or other law enforcement related issues, agencies and/or authorities; or
(iii) as is necessary to comply with any legal and/or regulatory obligation.

Security

We have implemented and maintained appropriate technical and organization security measures, policies and procedures designed to reduce the risk of accidental destruction or loss, or the unauthorized disclosure or access to Personal Data appropriate to the nature of such data. The measures we take include:
Safeguards – The physical, electronic, and procedural safeguards we employ to protect your Personal Data include secure servers, firewalls, antivirus, and SSL encryption of data.

Access Control – We dedicate efforts for a proper management of system entries and limit access only to authorized personnel on a need to know basis of least privilege rules, review permissions quarterly, and revoke access immediately after termination of our employees.

Internal Policies – We maintain and regularly review and update our privacy related and information security policies.

Personnel – We require new employees of ours to sign non-disclosure agreements according to applicable law and industry customary practice.

Encryption – We encrypt the data in transit using secure TLS/ SSL protocols.
Database Backup – Our databases are backed up on a periodic basis for certain data and are verified regularly. Backups are encrypted and stored within the production environment to preserve their confidentiality and integrity, are tested regularly to ensure availability, and are accessible only by authorized personnel.

However, no method of transmission over the Internet or method of electronic storage is 100% secure. Therefore, while we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security. As the security of information depends in part on the security of the computer you use to communicate with us and the security you use to protect user IDs and passwords, please take appropriate measures
to protect this information.

Your Rights – How to Access and Limit Our Use of Certain Personal Data

Subject to certain exemptions, and in some cases dependent upon the processing activity we are undertaking, you have certain rights in relation to the Personal Data that we or other controllers hold about you, as detailed below. We will investigate and attempt to resolve complaints and disputes and make every reasonable effort to honour your wish to exercise your rights as quickly as possible and, in any event, within the timescales provided by applicable data protection laws.

We reserve the right to ask for reasonable evidence to verify your identity before we provide you with any information and/or comply with any of your requests. If you are an Administrator or an Employee, for any requests to exercise such rights with respect to information we hold about you, please contact the applicable Customer directly.

• Right of Access. You have a right to know what Personal Data we collect about you and
in some cases, to have such Personal Data communicated to you. Subject to applicable law, we may charge you with a fee. Please note that we may not be able to provide you with all the information you request, and, in such case, we will endeavor to explain to you why.

• Right to Data Portability. If the processing is based on your consent or performance of a contract with you and processing is being carried out by automated means, you may be entitled to (request that we) provide you or another party with a copy of the Personal Data you provided to us in a structured, commonly-used, and machine-readable format.

• Right to Correct Personal Data. Subject to the limitations in applicable law, you may request that we update, complete, correct or delete inaccurate, incomplete, or outdated Personal Data.

• Deletion of Personal Data (“Right to Be Forgotten”). You have a right to request that we delete your Personal Data if either: (i) it is no longer needed for the purpose for which it was collected, (ii) our processing was based on your consent and you have withdrawn your consent, (iii) you have successfully exercised your Right to Object (see below), (iv) processing was unlawful, or (iv) we are required to erase it for compliance with a legal obligation. We cannot restore information once it has been deleted. Please note that to ensure that we do not collect any further Personal Data, you should also delete our App from your mobile devices, terminate your account with us, and clear our cookies from any device where you have used our Platform or an App. We may retain certain Personal Data (including following your request to delete) for audit and record-keeping purposes, or as otherwise permitted and/or required under applicable law

• Right to Restrict Processing: You can ask us to limit the processing of your Personal Data if either: (i) you have contested its accuracy and wish us to limit processing until this is verified;
(ii) the processing is unlawful, but you do not wish us to erase the Personal Data; (iii) it is no longer needed for the purposes for which it was collected, but we still need it to establish, exercise, or defend of a legal claim; (iv) you have exercised your Right to Object (below) and we are in the process of verifying our legitimate grounds for processing. We may continue to use your Personal Data after a restriction request under certain circumstances.

• Right to Object. You can object to any processing of your Personal Data which has our legitimate interests as its legal basis, if you believe your fundamental rights and freedoms outweigh our legitimate interests. If you raise an objection, we have an opportunity to demonstrate that we have compelling legitimate interests which override your rights and freedoms.

• Withdrawal of Consent. You may withdraw your consent in connection with any processing of your Personal Data based on a previously granted consent. This will not affect the lawfulness of any processing prior to such withdrawal.

 • Right to Lodge a Complaint with Your Local Supervisory Authority. You may have the right to submit a complaint to the relevant supervisory data protection authority if you have any concerns about how we are processing your Personal Data, though we ask that as a courtesy you please attempt to resolve any issues with us first.

Data Retention

Subject to applicable law, we retain Personal Data as necessary for the purposes set forth above. We may delete information from our systems without notice to you once we deem it is no longer necessary for these purposes. Retention by any of our processors may vary in accordance with the processor’s retention policy. In some circumstances, we may store your Personal Data for longer periods of time, for instance where we are required to do so in accordance with legal, regulatory, tax, audit, accounting requirements and so that we have an
accurate record of your dealings with us in the event of any complaints or challenges, or if we reasonably believe there is a prospect of litigation relating to your Personal Data or dealings.
To determine the appropriate retention period, we consider the amount, nature, and sensitivity of the Personal Data, the potential risk of harm from unauthorized use or disclosure of your Personal Data, the purposes for which we process your Personal Data, and whether those purposes can be achieved through other means, as well as applicable legal requirements. We retain Personal Data for as long as it is needed to provide you with the Platform, Apps, and Services.

Following deletion of your account, your Personal Data will be backed up for an additional period of 180 days. With respect to data of Administrators and Employees for which we serve as a processor, we will retain that data for as long as directed by the applicable Customer. For example, a Customer may choose to archive data of Administrators or Employees who have been terminated, in which case such archived data will be retained until deleted by the Customer.

Please contact us at contato@WeCheck.com.br if you would like details regarding the retention
periods for different types of your Personal Data.

Third-Party Applications and Services

All use of third-party applications or services is at your own risk and subject to such third party’s terms and privacy policies.

Communications

We reserve the right to send you service-related communications, including service announcements and administrative messages, without offering you the opportunity to opt out of receiving them. Should you not wish to receive such communications, you may cancel your account.

Children

We do not knowingly collect Personal Data from children under the age of sixteen (16). In the event that you become aware that an individual under the age of sixteen (16) has enrolled without parental permission, please advise us immediately.

Changes to the Privacy Notice

We may update this Privacy Notice from time to time to keep it up to date with legal requirements and the way we operate our business, and we will place any updates on this webpage. Please come back to this page every now and then to make sure you are familiar with the latest version. If we make fundamental changes to this Privacy Notice, we will seek to inform you by notice on our Site or by email.

Comments and Questions

If you have any comments or questions about this Privacy Notice or if you wish to exercise any of your legal rights as set out herein, please contact us at contato@WeCheck.com.br. We have appointed a data protection officer (DPO) who is responsible for overseeing our privacy practices.
If you have any comments or questions about this Privacy Notice, or if you wish to exercise any of your legal rights as set out herein, please contact using the details set out below:

Name of DPO: Bruno Barros
Email address: contato@WeCheck.com.br Last updated: January 2021