BOLD S.A. is committed to complying with the rules set out in the Brazilian General Data Protection Law (LGPD) and to respecting the principles established in Article 6:
I – Purpose: processing carried out for legitimate, specific and explicit purposes that are disclosed to the data subject, with no possibility of subsequent processing in a manner incompatible with those purposes;
II – Suitability: compatibility of the processing with the purposes disclosed to the data subject, in accordance with the context of the processing;
III – Necessity: limitation of the processing to the minimum required to fulfill its purposes, covering data that is relevant, proportional and not excessive in relation to the purposes of the data processing;
IV – Free access: guarantee to data subjects of easy and free consultation regarding the form and duration of the processing, as well as the entirety of their personal data;
V – Data quality: guarantee to data subjects of accuracy, clarity, relevance and updating of the data, according to the need and to fulfill the purpose of its processing;
VI – Transparency: guarantee to data subjects of clear, accurate and easily accessible information about the processing and the respective processing agents, subject to commercial and industrial secrecy;
VII – Security: use of technical and administrative measures capable of protecting personal data from unauthorized access and from accidental or unlawful destruction, loss, alteration, disclosure or dissemination;
VIII – Prevention: adoption of measures to prevent damage arising from the processing of personal data;
IX – Non-discrimination: impossibility of carrying out processing for unlawful or abusive discriminatory purposes;
X – Accountability: demonstration by the agent of the adoption of effective measures capable of proving compliance with personal data protection rules and, moreover, the effectiveness of those measures.
APPLICATION AND SCOPE
This applies to all data subjects who use the service or support channels by contacting us through the website or the service and support channels offered by BOLD S.A. and/or whose personal data is processed by us.
DEFINITIONS
Controller: The General Data Protection Law defines the controller in its Article 5:
Art. 5, VI – controller: natural or legal person, governed by public or private law, responsible for decisions regarding the processing of personal data;
Decisions regarding the processing of personal data are the responsibility of BOLD S.A.
Processor: The General Data Protection Law defines the processor in its Article 5:
Art. 5, VII – processor: natural or legal person, governed by public or private law, that processes personal data on behalf of the controller.
BOLD S.A. also acts as a processor, meaning that in addition to being responsible for decisions regarding the processing of the personal data it collects, it may also process personal data collected by its customers.
Data Protection Officer: The General Data Protection Law defines the officer in its Article 5:
Art. 5, VIII – person appointed by the controller and the processor to act as a communication channel between the controller, the data subjects and the National Data Protection Authority (ANPD).
BOLD S.A. appoints Marcelo Agrinfo as the officer responsible for personal data processing (DPO) and provides his contact details so that data subjects and the National Data Protection Authority (ANPD) can get in touch, through the email address dpo@bold.net .
RESPONSIBILITIES
WHICH PERSONAL DATA DOES BOLD PROCESS?
The amount and the types of data collected vary according to the nature of the relationship the personal data subject has with BOLD S.A. We will collect different data if the data subject is only a website visitor, is requesting a service proposal, or is already using the services offered by BOLD S.A.
IS THE PERSONAL DATA USED SHARED?
The personal data of the data subject may be shared with partner companies and service providers in order to deliver our services.
SECURITY IN THE PROCESSING OF THE PERSONAL DATA OF THE DATA SUBJECT
BOLD S.A. is committed to applying technical and organizational measures capable of protecting personal data from unauthorized access and from situations of destruction, loss, alteration, disclosure or dissemination of such data.
To ensure security, solutions will be adopted that take into account: appropriate techniques; implementation costs; the nature, scope, context and purposes of the processing; and the risks to the rights and freedoms of the data subject.
Data collection takes place securely, so that the transmission of data between the systems involved and the data subject is fully encrypted.
BOLD S.A. is released from liability in cases of exclusive fault of the data subject, when the subject transfers their own data to a third party. BOLD S.A. further undertakes to notify the data subject within a reasonable time frame if any breach of the security of their personal data occurs that may cause a high risk to their personal rights and freedoms.
A personal data breach is a security breach that causes, accidentally or unlawfully, the destruction, loss, alteration, disclosure or unauthorized access to personal data that is transmitted, stored or subject to any other type of processing.
Finally, BOLD S.A. is committed to processing the personal data of the data subject with confidentiality, within legal limits.
DOES THE BOLD WEBSITE USE COOKIES?
Cookies are small text files sent by the website to the data subject’s computer and stored there with information related to browsing on the site.
Through cookies, small amounts of information are stored by the user’s browser so that our server can read them later. For example, data about the device used by the user may be stored, as well as the place and time of access to the site.
It is important to point out that not every cookie contains personal data of the data subject, since certain types of cookies may be used solely so that the service works properly.
Any information stored in cookies is also considered personal data, and all the rules set out in this Privacy Policy also apply to it.
ON THE END OF PERSONAL DATA PROCESSING
In accordance with the LGPD (art. 15 and 16), the end of personal data processing by BOLD S.A. will occur in the following situations:
I – Verification that the purpose has been achieved or that the data is no longer necessary or relevant to achieving the specific intended purpose;
II – End of the processing period;
III – Notice from the data subject regarding the withdrawal of consent, subject to the public interest; or
IV – Determination by the national authority, when there is a violation of personal data protection.
BOLD S.A. processes personal data for as long as necessary to fulfill the purpose for which it was collected, according to its legal basis. At the end of the processing, the personal data will be deleted, with retention authorized in the situations provided for by applicable law.
THIS PRIVACY POLICY MAY BE CHANGED
BOLD S.A. reserves the right to modify these rules at any time, especially in order to adapt them to developments in the services provided to its customers, whether through the release of new services or through the removal or modification of existing ones.
Any change and/or update to this Privacy Policy will take effect from the date it is published on the BOLD S.A. website and must be fully observed by users, which is why we advise the data subject to review this document periodically.
WHICH JURISDICTION APPLIES IF THE DATA SUBJECT WISHES TO FILE A COMPLAINT
Without prejudice to any other administrative or judicial remedy, all data subjects have the right to file a complaint with the National Data Protection Authority.
HOW TO ASK QUESTIONS OR EXERCISE YOUR RIGHTS AS A DATA SUBJECT
The General Data Protection Law establishes that the personal data subject has the right to obtain from the controller, in relation to the subject’s data processed by it, at any time and upon request:
I – Confirmation of the existence of the processing; II – Access to the data;
III – Correction of incomplete, inaccurate or outdated data;
IV – Anonymization, blocking or deletion of unnecessary or excessive data or data processed in noncompliance with the provisions of this Law;
V – Portability of the data to another service or product provider, upon express request, in accordance with the regulations of the national authority, subject to commercial and industrial secrecy;
VI – Deletion of personal data processed with the consent of the data subject, except in the situations provided for in art. 16 of this Law;
VII – Information about the public and private entities with which the controller has shared data;
VIII – Information about the possibility of not giving consent and about the consequences of refusal;
IX – Withdrawal of consent.
X – Objection to processing carried out on the basis of one of the situations in which consent is waived, in the event of noncompliance with the provisions of this Law.
If you have any questions about this privacy policy or wish to exercise your rights as a data subject, please contact our Data Protection Officer (DPO) at the email address dpo@bold.net.
Controlled copy
DATA PRIVACY POLICY
Date of Preparation: 07/24/2023 Revision: 00 Code: TI-POL-0002 Page: 8 of 8
DEVIATIONS AND REQUIRED ACTIONS
Failure to comply with the requirements set out in the Data Privacy Policy will constitute a violation of the internal rules of BOLD S.A. and will subject the person to the applicable administrative and legal measures.
GENERAL CONSIDERATIONS
The content of this document is the property of BOLD S.A. and is intended for public use and disclosure.
It must not be reproduced, stored or transmitted in any format or by any means, whether electronic or physical, without the prior authorization of BOLD S.A.
Compliance with the document may be subject to periodic auditing in order to monitor its use.
Any incident that puts the privacy of information assets at risk must be reported immediately and formally to the DPO, so that the situation can be assessed and the necessary measures taken.
Any changes to the company’s processes and routines must be made in compliance with this Policy.
This document cancels and replaces any previous communication about the Data Privacy Policy of BOLD S.A. Cases not covered by this policy must be referred to and handled directly by the DPO of BOLD S.A.
Cookie Policy
This Cookie Policy is a document that complements the Data Privacy Policy available on the BOLD S.A. website. In the Cookie Policy you will find clear, objective information about what cookies are, which cookies we use in our applications, what role they play and how to configure them.
APPLICATION AND SCOPE
This applies to all data subjects who use the service or support channels by contacting us through the website or the service and support channels offered by BOLD S.A. and/or whose personal data is processed by us.
DEFINITIONS
WHAT ARE COOKIES?
Cookies are small text files or pieces of information that are downloaded to your computer, smartphone or any other type of internet-enabled device when you visit our applications.
They contain information about your browsing on our pages and retain only information related to your preferences.
This allows the page to store and retrieve data about your browsing habits in order to improve the user experience, for example. It is important to stress that they do not contain specific personal information, such as sensitive or banking data.
Your browser stores cookies on the hard drive, but they take up a minimal amount of memory that does not affect your computer’s performance. Most of the information is deleted as soon as the session ends, as you will see in the next topic.
TYPES OF COOKIES
In terms of ownership, cookies may be:
First-party cookies: cookies set by us or by third parties on our behalf.
Third-party cookies: cookies set by trusted third parties within our application.
In terms of lifespan, cookies may be:
Session or temporary cookies: cookies that expire as soon as you close your browser, ending the session.
Persistent or permanent cookies: cookies that remain on your device for a set period or until you delete them.
In terms of purpose, cookies may be:
Necessary cookies: essential cookies that make it possible to browse our applications and access all features; without them, our services may perform poorly or not work at all.
Performance cookies: cookies that optimize the way our applications work by collecting anonymous information about the pages visited.
Functionality cookies: cookies that remember your preferences and choices (such as your user name, if you allow it).
Advertising cookies: cookies that target ads based on your interests and limit the number of times an ad is shown.
WHY DO WE USE COOKIES?
BOLD S.A. uses cookies to provide the best user experience, making our applications friendlier and more personalized based on your choices and browsing behavior.
In this way, we seek to understand how you use our applications and to adjust the content to make it more relevant to you, as well as to improve your interaction experience by storing your preferences.
Cookies take part in this process because they store, read and run the data needed to fulfill our goal.
WHAT TYPES OF COOKIES DO WE USE?
Below we list all the cookies that may be used by BOLD S.A. It is important to remember that you can manage the permission granted to each cookie in your browser.
In addition, since cookies capture data about you, we recommend reading our Data Privacy Policy, available on our website.
NECESSARY COOKIES
Strictly necessary cookies
These are the cookies required for our website to work. They include, for example, cookies that allow visitors to browse secure areas of the site:
AWS
Akamai Drupal
Technologies based on Microsoft NET
Performance cookies
They make it possible to recognize and count the number of visitors and to see how they move around our website when using it. This helps improve how our website works, for example by making sure users can easily find what they are looking for:
Google Analytics RD Station Hotjar
Functional cookies
These are used to recognize users when they return to our website. This makes it possible to personalize our content for users by remembering their preferences, such as their choice of language or region:
Commerce
Third-party targeting cookies
Third parties (including, for example, our affiliates, advertising networks, social networks and external service providers such as web traffic analysis services) may also use cookies over which we have no control and which are governed by the specific privacy or cookie policy of each third party. Those used on this site are:
Facebook YouTube RD Station Google
RESPONSIBILITIES COOKIE MANAGEMENT
The installation of cookies is subject to your consent. Although most
browsers are initially set to accept cookies automatically, you can review your permissions at any time in order to block them, accept them or enable notifications for when certain cookies are sent to your device.
Currently, the first time you access our applications, you will be asked to agree to their installation. They will only be activated after your acceptance.
To do so, we use an information banner system on the BOLD S.A. home page. In this way, we not only ask for your agreement but also inform you that continued browsing on our sites will be understood as consent.
As already stated, you may change permissions, block or refuse cookies at any time and at no cost. However, withdrawing consent for certain cookies may prevent some platform features from working properly.
To manage the cookies in your browser, simply do so directly in the browser settings, in the cookie management area.
You can access tutorials on the subject directly through the links below: If you use Internet Explorer.
If you use Firefox.
If you use Safari.
If you use Google Chrome.
If you use Microsoft Edge.
If you use Opera.
GENERAL CONSIDERATIONS
The content of this document is the property of BOLD S.A. and is intended for public use and disclosure.
Controlled copy
COOKIE POLICY
Date of Preparation: 08/09/2023 Revision: 00 Code: TI-POL-0003 Page: 7 of 7
It must not be stored or transmitted in any format or by any means, whether electronic or physical, without the prior authorization of BOLD S.A.
Compliance with the document may be subject to periodic auditing in order to monitor its use.
Any incident that puts the privacy of information assets at risk must be reported immediately and formally to the DPO, so that the situation can be assessed and the necessary measures taken.
Any changes to the company’s processes and routines must be made in compliance with this Policy.
This document cancels and replaces any previous communication about the Data Privacy Policy of BOLD S.A. Cases not covered by this policy must be referred to and handled directly by the DPO of BOLD S.A. at the email address dpo@bold.net.
This version of this Cookie Policy was last updated on: 08/30/2023.