Personal Data Protection Policy

MTrix

Personal Data Protection Policy v1

MTrix Tecnologia e Serviços de Marketing S.A. (“MTrix“) values your privacy and personal data. Therefore, it is important that you read these rules so that you can knowingly benefit from the security conditions we offer through our various services.

This Personal Data Protection Policy (“Policy”) explains your rights and our obligations regarding the processing of personal data collected from users like you while using our services.

This Policy applies to personal data processing carried out through our website, mobile applications, and services in general.

If you do not agree with this Policy, do not access or use our websites, applications, or Services. Your access and use of these resources will automatically indicate that you have read and agreed to this Policy.

MTrix does not authorize children or minors to use its Services.

  1. Definitions
  • Data Processing: Any operation performed on Personal Data, including collection, production, use, access, transmission, processing, storage, and deletion.
  • LGPD: Brazilian Federal Law No. 13,709/2018 (General Data Protection Law), which governs data protection rights and obligations in Brazil.
  • Data Subject: An identified or identifiable natural person to whom the Personal Data relates.
  • Controller: A natural or legal person responsible for decisions regarding the processing of Personal Data.
  • Joint Controller: A third party that receives shared data from the Controller to jointly process it or process it for its own purposes.
  • Processor: A natural or legal person that processes Personal Data on behalf of the Controller.
  • Data Protection Officer (DPO): A natural or legal person responsible for handling requests from Data Subjects and the Brazilian National Data Protection Authority (ANPD).
  • Purpose: The objective the Controller intends to achieve through the processing of Personal Data.
  • Consent: A free, informed, and explicit authorization by which the Data Subject agrees to the processing of their Personal Data for a specific purpose. Consent may be withdrawn at any time, without affecting processing carried out before withdrawal.
  • Client: A legal entity that contracts MTrix to provide services.
  • User: A natural person who uses MTrix services.
  • Client User: A natural person who uses MTrix services on behalf of a Client.
  • Services: Collection, processing, and delivery of transactional sales and inventory data through business intelligence solutions provided via online platforms, reports, market studies, mobile applications (MTrix App), and websites.
  • Partners: Legal entities with which MTrix maintains contractual relationships for service provision or personal data processing activities.
  1. What Are Personal Data?

“Personal Data” means any information relating to an identified or identifiable individual.

An individual is considered identifiable when:

  1. MTrix possesses direct identifying information, such as a name or full address; and/or
  2. It is reasonably likely that MTrix can identify the individual through other means, such as a registration number linked to a name or address.

If Personal Data relates to racial or ethnic origin, religious beliefs, political opinions, union membership, religious, philosophical or political affiliations, health, sexual life, genetic data, or biometric data, it is classified as Sensitive Personal Data.

  1. Obligations of Employees and Suppliers

All employees and, where applicable, suppliers must comply with this Policy and any related MTrix corporate policies.

Failure to comply may result in disciplinary action.

  1. Information About the Processing of Your Personal Data

4.1 During the Use of Our Website

MTrix collects Personal Data to:

  • Promote MTrix products and services.
  • Interact with users regarding inquiries.
  • Conduct marketing and advertising campaigns.
  • Identify, authenticate, and support Client Users.
  • Fulfill contractual obligations.
  • Protect MTrix’s rights and obligations.

The following Personal Data may be collected:

  • First and last name
  • Email address
  • Telephone number
  • Employer/company name
  • Job title
  • Industry or area of work
  • Estimated company revenue

The Data Subject is responsible for the accuracy and updating of the information provided.

Navigation Data and Cookies

MTrix may collect:

  • IP address
  • Source port and geolocation
  • User actions
  • Accessed screens/pages
  • Date and time of activities
  • Device information, including operating system version, browser, geolocation, and installed applications
  • Session ID
  • Interaction and operation history

MTrix may also receive data from Clients or related entities, including:

  • Residential address
  • CPF (Brazilian taxpayer identification number)
  • Photos or videos

In such cases, the Client acts as the Controller and is responsible for obtaining any necessary consent.

If users are redirected to third-party platforms, MTrix is not responsible for data processing carried out by those third parties.

4.2 During the Use of Our Applications

To provide services, authenticate users, and personalize the user experience, MTrix may process:

  • Email address
  • Telephone number
  • Usage preferences
  • Browsing data
  • Information submitted through forms

This information may also be used to improve applications and generate anonymous statistical analyses.

Users may choose whether or not to receive communications regarding MTrix offers, products, and services.

4.3 During the Use of Our Services

To provide and improve our Services, MTrix may process:

  • Full name
  • Job title
  • Email address
  • Registration details
  • Browsing and activity information

Users may consent to receive information about products and services.

4.4 Data Processed on Behalf of Clients

MTrix may process sales-related information on behalf of Clients.

Unless expressly requested by a Client, MTrix does not process Personal Data relating to identified or identifiable individuals for such purposes.

Clients, as Controllers, are responsible for informing Data Subjects and obtaining any required consent.

  1. General Information

MTrix is committed to:

  • Processing Personal Data only for legitimate purposes.
  • Applying the principles of data minimization and necessity.
  • Complying with applicable data protection laws.
  • Informing users of significant changes to processing activities.
  • Respecting users’ rights and freedoms whenever processing is based on legal grounds other than consent.

Passwords and Security

MTrix maintains safeguards designed to protect Personal Data against:

  • Unauthorized access
  • Unlawful processing
  • Loss
  • Destruction
  • Damage

Users are responsible for defining and protecting their login credentials.

MTrix:

  • Restricts access to Personal Data to authorized personnel.
  • Will never request your password.
  • Maintains an Information Security Incident Response Plan.

If you suspect a privacy or security incident, contact the DPO immediately.

Consent

Where required by the LGPD, MTrix will obtain consent before processing Personal Data.

Consent is generally requested for:

  • Marketing campaigns
  • Product and service promotion
  • Statistical and behavioral studies

Consent may be withdrawn at any time by contacting the DPO.

  1. Retention Period for Personal Data

MTrix stores Personal Data:

  • For as long as necessary to provide the Services; and
  • For up to five (5) years after the end of the relationship, except where longer retention is required or permitted by law.

After that period, Personal Data will be permanently deleted.

Accounts will be cancelled and access revoked after the end of the relationship with MTrix.

  1. Accountability

MTrix maintains records of data processing activities as required by the LGPD.

Where appropriate, MTrix may conduct Data Protection Impact Assessments (DPIAs) to identify and mitigate risks.

MTrix’s responsibilities are limited to adopting appropriate good practices and security measures in accordance with Article 32 of the LGPD.

  1. Sharing Personal Data with Third Parties

Personal Data may be shared with:

  • Courts and government authorities when required by law.
  • Companies involved in mergers, acquisitions, or corporate restructuring.
  • Hosting, cloud, software, telecommunications, maintenance, and IT service providers.
  • Consulting firms.
  • Advertising agencies.
  • Telephone and mobile communication providers.
  • Postal services and logistics providers.
  • Financial and insurance service providers.
  • Travel agencies.
  • Event management providers.
  • Marketing platforms.
  • Business partners.
  • Recipients of services that require the use of such data.

All third parties receiving Personal Data are subject to confidentiality and/or data protection obligations, except public authorities where legally applicable.

International Transfers

Some service providers may operate outside Brazil.

Currently, Personal Data may be transferred to cloud infrastructure located in the United States, under contractual safeguards designed to protect users’ rights and freedoms.

  1. Data Subject Rights

Under Article 18 of the LGPD, Data Subjects may request:

  1. Confirmation of processing
  2. Access to Personal Data
  3. Correction of incomplete, inaccurate, or outdated data
  4. Anonymization, blocking, or deletion of unnecessary or unlawfully processed data
  5. Data portability
  6. Deletion of data processed based on consent
  7. Information about entities with whom data is shared
  8. Information about the consequences of refusing consent
  9. Withdrawal of consent

Requests should include the Data Subject’s:

  • Full name
  • CPF
  • Confirmation email address

MTrix may request additional information to verify identity.

Requests will generally be answered within 15 days, or another period permitted under applicable law.

  1. Data Protection Officer (DPO)

Questions regarding this Policy or requests related to LGPD rights should be directed to:

contato.lgpd@mtrix.com.br

  1. Final Provisions

Technological developments, market requirements, or legal changes may require updates to this Policy.

When significant changes occur, MTrix will notify Data Subjects in advance.

If renewed consent is required, users will be notified electronically.

Should any provision of this Policy be deemed invalid, the remaining provisions shall remain in force.

The Data Subject agrees that electronic communication channels, including email, SMS, and messaging applications, are valid forms of communication.

For Data Subjects not domiciled in Brazil, the courts of São Paulo, Brazil, shall have exclusive jurisdiction over disputes relating to this Policy.

Effective Date of this Policy: December 22, 2021.