Privacy and Data Protection Policy

This Policy describes how SUMAQ Comunicação Financeira S.A. processes personal data in connection with the use of our website, commercial relationships, and the provision of services, including projects involving the implementation and integration of solutions such as the Workiva platform. Here you will find information about what data may be collected, where it may come from, the purposes for which it is processed, with whom it may be shared, how long it may be retained, and your rights as a data subject.

SUMAQ adopts governance, information security, and privacy practices to ensure that processing is transparent, limited to what is necessary, and aligned with applicable legislation.

1. Scope of this Policy

This Policy applies:

  • To access and navigation on websites under the SUMAQ domain.
  • To relationships with leads, prospects, clients, partners, and suppliers, including digital channels, events, and commercial prospecting activities.
  • To the execution of contracts and projects, including deployment, support, integration, automation, and technical activities.
  • To communication with authorized users in environments and solutions used in projects.

2. Roles and responsibilities (Controller and Processor)

Depending on the context, SUMAQ may act as:

  • Controller of personal data: when it determines the purposes and means of processing (e.g., data collected on the website, commercial contacts and prospecting, relationship management, customer service, and institutional communications).
  • Processor of personal data: when it processes data on behalf of the client, in accordance with contractual instructions and for the execution of services (e.g., implementation projects, loading and integrating data into client platforms).

3. Categories of personal data processed

SUMAQ may process, as applicable:

  • Identification and contact data: name, email, phone number, company, and job title.
  • Professional and prospecting data: company or organization, professional area, job title or role, source of the contact, relationship history, and preferences related to commercial communications.
  • Navigation data: IP address, date and time of access, pages visited, device and browser identifiers.
  • Relationship and service data: interaction history, requests, support records, and communications.
  • Project data: information required to deploy and operate contracted services. This may include, on a limited basis, corporate personal data of authorized users (e.g., corporate email and access identifiers), as well as the client's operational and financial data.

SUMAQ does not intentionally process payment card data (e.g., card number, CVV, expiration date) and does not use sensitive personal data for commercial prospecting purposes. If you identify any improper submission of information, we recommend that you do not share it and that you contact us immediately.

4. Purposes and legal bases for processing

Personal data may be processed for the purposes below, as applicable, using the legal bases provided for by applicable law:

  • Performance of a contract and preliminary procedures: delivery of services, deployment, integrations, support, and contractual obligations.
  • Legitimate interests: relationships with clients and prospects, B2B commercial prospecting, development and promotion of SUMAQ's activities, process improvement, fraud prevention, and security, while respecting the rights and fundamental freedoms of data subjects and, where applicable, assessing purpose, necessity, and balancing.
  • Consent: when required for a particular activity, specific promotional communication, non-essential technology, or when required by applicable law or by the rules governing the communication channel used.
  • Compliance with a legal or regulatory obligation: when applicable, especially in regulatory contexts.
  • Exercise of rights: when necessary to protect SUMAQ's rights in administrative, judicial, or arbitration proceedings.

In projects, processing is limited to the purposes defined in the contract and the client's instructions. If an additional purpose is required, SUMAQ assesses compatibility and adequacy, observing purpose limitation, necessity, and data minimization.

5. Commercial prospecting and data sources

To identify companies and professionals who may be interested in our products and services, SUMAQ may carry out B2B commercial prospecting activities and process professional and contact data compatible with this purpose.

Data used for these activities may be obtained directly from the data subject or through legitimate sources and third parties, always considering the purpose, the nature of the data, the reasonable expectations of the data subject, and the principles of necessity, transparency, and data minimization.

  • Data provided directly by the data subject, including through forms, events, meetings, demonstrations, contact requests, and commercial interactions.
  • Public or legitimately accessible sources, such as institutional websites, publicly available professional information, and public databases permitted by applicable law.
  • Partners, referrals, and professional events, when compatible with the stated purpose or the reasonable expectations of the data subject.
  • Market intelligence, data enrichment, or professional data providers, subject to compliance assessment, purpose adequacy, and data protection requirements.

The fact that data is publicly available does not exclude the application of data protection laws. SUMAQ considers the context in which the data was made available, the purpose of its use, and the rights of the data subject. Data subjects may request that commercial communications cease through the mechanisms made available in the communication itself or through lgpd@sumaq.com.br.

6. Public, internal, and confidential information

In the context of the services provided, information may be classified in different ways:

  • Public information: data and documents that are already public or will be disclosed at the end of a process (e.g., regulatory reports and publications).
  • Internal and confidential information: operational, preliminary, unpublished, or restricted data used for the execution, validation, and approval of projects.

SUMAQ maintains controls to ensure that internal and confidential information is accessed only by authorized persons based on need-to-know and project responsibilities.

7. Data sharing and third parties

SUMAQ does not sell personal data. Data may be shared only when necessary and proportionate to the purposes described in this Policy, for example:

  • With infrastructure and technical service providers (e.g., hosting, corporate email, and support tools), when applicable.
  • With CRM, sales automation, communications, market intelligence, and data enrichment providers used to support commercial and relationship activities.
  • With platforms used by the client in a project (e.g., Workiva), in accordance with the contractual scope and the client's instructions.
  • With partners or service providers that support SUMAQ's activities, when necessary and compatible with the purpose of the processing.
  • With competent authorities pursuant to a legal or regulatory obligation or a valid request.

When suppliers or sub-processors are involved, SUMAQ adopts assessment processes and, where applicable, contractual instruments to define responsibilities, confidentiality, and security and privacy requirements.

8. International data transfers

Where personal data is transferred internationally, such transfers will be carried out in a controlled manner and in accordance with applicable legal requirements, including appropriate contractual mechanisms and security measures, and limited to what is necessary for the purpose of the processing.

9. Cookies and tracking technologies

The website may use cookies and similar technologies for essential functionality, security, and experience improvement. Non-essential cookies may depend on consent, where applicable.

You can manage cookies through your browser settings. Disabling essential cookies may affect the operation of the website.

10. Information security

SUMAQ adopts technical and organizational security measures to protect personal data and business information against unauthorized access, loss, improper alteration, or disclosure, including access controls, traceability, segregation of duties, and good operational practices.

11. Retention, disposal, and suppression list

Personal data is retained only for as long as necessary to fulfill the purposes of this Policy, contractual and legal obligations, and to safeguard rights in potential claims. After this period, data is deleted or anonymized, where applicable.

Data used for commercial prospecting and relationship purposes is retained while it remains adequate, relevant, and necessary for that purpose, subject to periodic review. When a data subject requests that commercial communications cease, SUMAQ may retain minimum information in a suppression list solely to record that preference and prevent inappropriate future contact.

12. Data subject rights and service channel

You may exercise the rights provided by applicable law, including, as applicable, confirmation of processing, access to data, correction of incomplete, inaccurate, or outdated data, anonymization, blocking, or deletion of unnecessary, excessive, or unlawfully processed data, portability subject to applicable regulation, information about data sharing, information about the possibility of refusing consent and its consequences, withdrawal of consent, and objection to processing in the circumstances provided by law.

You may also request information about the source of the data, the criteria used, and the purpose of the processing, where applicable, as well as request that commercial communications cease.

To exercise your rights or clarify questions, use the following channel: Email: lgpd@sumaq.com.br

13. Data Protection Officer (DPO) and contact

SUMAQ's Data Protection Officer (DPO) is André Ourives. Contact channel: lgpd@sumaq.com.br

The DPO acts as a point of contact for data subjects and authorities, supports privacy governance, provides guidance on good practices, and cooperates, where applicable, in impact assessments and matters related to data protection.

14. Updates to this Policy

This Policy may be updated to reflect legal, technological, or operational changes. We recommend periodically reviewing this page. Relevant changes may be communicated through appropriate means.

Last updated: September 25, 2026.