Privacy Policy

Privacy and Personal Data Protection Policy

TAGD 20 YEARS — ATTORNEYS

1. PURPOSE

At Terciotti Andrade Gomes Donato Advogados (“TAGD”, the “Firm”, or “we”), we are committed to protecting the personal information (personal data) of users (data subjects) to which we have access in the course of our activities. This Privacy and Personal Data Protection Policy (the “Policy”) is intended to explain, objectively and transparently, how we handle personal data in our activities. Any processing of personal data in the course of our activities is conducted in accordance with best practices and applicable law, in particular the Brazilian General Data Protection Law (Law No. 13.709/2018 — “LGPD”).

2. WHO WE ARE

We are attorneys practicing throughout Brazil, with offices in the City of Rio de Janeiro, State of Rio de Janeiro, at Avenida das Américas, 3.500, Bl 2, Sl 509 a 516, Barra da Tijuca, CEP 22.640-102, and Avenida Rio Branco, 143, 17º andar, Centro, CNPJ/ME nº 19.707.479/0001-29; in the City of São Paulo, State of São Paulo, at Rua Pedroso Alvarenga, 691, Conjunto 608, Itaim Bibi, CEP 04.531-011, CNPJ/ME nº 28.898.654/0001-01; and in the City of Belém, State of Pará, at Travessa Rui Barbosa, 897, CEP 66053-260.

3. CONTACT US

If you have any questions about this Policy, wish to contact TAGD to correct any of your registered information, or wish to exercise your rights, you may contact our Data Protection Officer and Deputy Data Protection Officer (“DPO” and “Deputy DPO”):

  • Name: Patricia Hermont Barcellos Gonçalves Madeira
  • Email: compliance@tagdlaw.com.br

4. PRIVACY AND PERSONAL DATA PROTECTION COMMITTEE

TAGD shall maintain a permanent Privacy and Personal Data Protection Committee, which may be composed of the DPO and designated partners and associates. The Committee shall review matters relating to privacy and personal data protection and serve as a forum for keeping abreast of and discussing developments in this field.

5. APPLICATION AND INTERPRETATION OF THIS POLICY

Italicized words and expressions have the meanings assigned to them under the LGPD. A brief explanation and examples of such words and expressions are provided at the end of this Policy. References in this Policy to personal data include sensitive personal data (such as data relating to gender, ethnicity, health, and other matters) that we may process. This Policy must be observed by our partners, associates, consultants, employees, interns, suppliers, service providers (including temporary providers), and business partners (the “Policy Recipients”).

6. AMENDMENTS TO THIS POLICY

This Policy may be updated and amended from time to time and shall be reviewed whenever necessary to reflect technological advances, changes in legislation, and market developments. The latest version of this Policy will always be made available on our website. Last updated: January 21, 2022.

7. PRINCIPLES GOVERNING THE PROCESSING OF PERSONAL DATA

  • (i) Purpose: personal data are processed by us for legitimate, specific, explicit purposes of which the data subject has been informed, in accordance with the legal bases established under the LGPD, namely: the data subject’s consent; compliance with a legal or regulatory obligation by the controller; processing and shared use of data by the Public Administration where necessary to implement public policies provided for in laws and regulations or supported by contracts, agreements, or similar instruments; studies conducted by a research body, with anonymization of personal data whenever possible; where necessary for the performance of a contract or preliminary procedures relating to a contract to which the data subject is a party, at the data subject’s request; the regular exercise of rights in judicial, administrative, or arbitration proceedings; protection of the life or physical safety of the data subject or a third party; protection of health, exclusively in procedures carried out by healthcare professionals, healthcare services, or health authorities; pursuit of the legitimate interests of the controller or a third party, except where the data subject’s fundamental rights and freedoms requiring the protection of personal data prevail; or credit protection, including as provided under applicable law;
  • (ii) Adequacy and Necessity: the processing of personal data shall be compatible with the purposes disclosed to the data subject, having regard to the context of the processing. The personal data collected shall be limited to those necessary to conduct our activities and shall be processed in accordance with the legitimate and specific purposes for which they are intended;
  • (iii) Free Access: we provide data subjects with facilitated and free access to information concerning the form and duration of processing, as well as the entirety of their personal data;
  • (iv) Data Quality: we ensure that data subjects’ personal data are accurate, clear, relevant, and up to date, as necessary and in order to fulfill the specific purposes of the processing.
  • (v) Transparency: we provide data subjects with clear, accurate, and readily accessible information concerning the processing and the relevant processing agents, subject to TAGD’s right to protect its trade secrets and contractual obligations and to the confidentiality governing attorney-client relationships.
  • (vi) Security and Prevention: we process personal data using appropriate technical and organizational measures for their protection and preservation, in order to prevent destruction, loss, alteration, disclosure, or dissemination.
  • (vii) Non-Discrimination: our processing of personal data is not conducted for any discriminatory, unlawful, or abusive purpose.
  • (viii) Accountability: we implement demonstrably effective technical and organizational measures to protect the data we process and to comply with applicable personal data protection rules. In addition, we have a team wholly dedicated to technology and information security matters.

8. PERSONAL DATA WE COLLECT AND PROCESS

In conducting our activities and providing services to our clients, we process various types of personal data, always for specific, legitimate, and appropriate purposes, including, without limitation:

  • (i) Data relating to clients that retain the Firm’s services, such as name, registration and identification data (CPF and RG), address, email address, and job title;
  • (ii) Data relating to prospective clients who may or may not retain the Firm, such as name, email address, and job title;
  • (iii) Data relating to the Firm’s partners, associates, consultants, employees, and interns, as required for various purposes, including amendments to its articles of association, making payments, and allocating work, such as name, CPF, and address;
  • (iv) Data relating to candidates for attorney, intern, or employee positions, provided through résumé submissions;
  • (v) Data relating to suppliers and providers of materials and services to the Firm, for performance of the relevant supply or service agreements, such as name, CPF, and address;
  • (vi) Data relating to users who browse the Firm’s website, which uses cookies (see the Cookies section below), such as IP address and geolocation data;
  • (vii) Data relating to LinkedIn users who access the Firm’s profile or send messages directly through the platform, such as name and job title.

9. WHAT RIGHTS DO PERSONAL DATA SUBJECTS HAVE?

We shall respond, at the data subject’s request and through the email address provided at the beginning of this Policy, to requests concerning inaccurate or outdated information. In certain circumstances, TAGD must respond immediately to requests by data subjects seeking to exercise their rights under the LGPD. If TAGD is unable to comply immediately, the data subject shall be notified within 15 (fifteen) days or within such other period as may be prescribed by the Brazilian National Data Protection Authority (Autoridade Nacional de Proteção de Dados — “ANPD”).

If an immediate response is not possible, TAGD shall promptly notify the data subject, as applicable, that TAGD is not a data processing agent (controller or processor) and, whenever possible, identify the responsible agent; or explain the factual or legal grounds preventing an immediate response that fully addresses the data subject’s request.

With respect to the rights to confirmation of processing or access to personal data, TAGD shall respond immediately in simplified form or, within 15 (fifteen) days, by means of a clear and complete statement indicating the origin of the data, any absence of records, the criteria applied, and the purpose of the processing, subject to TAGD’s right to protect its trade secrets and contractual obligations and to the confidentiality governing attorney-client relationships. To ensure that the person making the request is the data subject to whom the requested data relate, the request must be accompanied by proof of identity, and we may require additional verification measures. This is a security measure designed to prevent the inadvertent disclosure of personal data. TAGD may also contact the data subject to request further information concerning the request.

In each of the foregoing circumstances, we shall keep the data subject informed of the status of the relevant request. Data subjects have the following rights:

  • (i) Confirmation of Processing: if a data subject is uncertain whether TAGD processes his or her personal data, the data subject may request confirmation of that fact.
  • (ii) Access to Data: a data subject may request access to his or her personal data from TAGD. A list of the categories of personal data being processed shall be provided. If the processing was based on consent or a contract, the data subject may also request a complete copy of all of his or her personal data held by TAGD, subject to TAGD’s right to protect its trade secrets and contractual obligations.
  • (iii) Correction of Incomplete, Inaccurate, or Outdated Personal Data: a data subject may request that TAGD rectify his or her personal data in TAGD’s records.
  • (iv) Anonymization, Blocking, or Deletion: if a data subject believes that any of his or her personal data are unnecessary, excessive, or processed in violation of law, the data subject may exercise this right. Applicable law may permit processing to continue even after a request for anonymization, blocking, or deletion.
  • (v) Data Portability: in certain circumstances, a data subject may request the transfer of his or her personal data to another controller. TAGD reserves the right not to transfer personal data relating to its trade secrets and to retain such data in accordance with the appropriate legal bases.
  • (vi) Deletion of Personal Data Processed with the Data Subject’s Consent: except in the following circumstances: compliance with a legal or regulatory obligation by the controller; studies conducted by a research body, with anonymization of personal data whenever possible; transfer to a third party, provided that the personal data processing requirements under applicable law are observed; or exclusive use by the controller, provided that access by third parties is prohibited and the data are anonymized.
  • (vii) Information on the Entities and Countries with Which TAGD Shares Personal Data: the data subject may request such information.
  • (viii) Information on the Right to Withhold Consent and the Consequences of Doing So: where consent is required for processing, TAGD shall inform the data subject of the right to withhold consent and the consequences of doing so.
  • (ix) Withdrawal of Consent: whenever processing is based on consent, the data subject may withdraw that consent at any time. From that time onward, TAGD shall cease processing the data subject’s personal data, except with respect to personal data already processed or where another legal basis permits TAGD to continue processing such data.

10. INFORMATION SECURITY

We implement technical and organizational measures to protect the personal data we process and use our best efforts to prevent unauthorized access and accidental or unlawful destruction, loss, alteration, disclosure, or dissemination. We also seek to ensure that all third parties with whom we work keep personal data safe and secure. We use only cloud service providers and software that meet minimum information-security requirements sufficient to protect stored data.

We maintain access controls for users of our information-technology systems to ensure that access is restricted to persons authorized to access such data, as necessary to perform their activities at TAGD, in accordance with the principle of least privilege (“need to know”). Our partners, associates, employees, and interns are also instructed to keep physical documents containing personal data in drawers, cabinets, or other compartments that provide appropriate storage and protection, rather than on desks or in printers; not to share login credentials or passwords for their respective workstations; and to lock their computers when away from their workstations in order to prevent unauthorized access to personal data by third parties.

We also perform periodic offline backups to ensure that the Firm’s files are stored securely. We use complex passwords to access information-technology systems. Passwords are updated periodically and are not shared with third parties. We periodically scan all information-technology systems in use, and emails sent and received by us are protected by anti-spam and antivirus tools.

11. SHARING PERSONAL DATA WITH THIRD PARTIES

The Firm shall share, transfer, or disclose personal data to third parties only to the extent strictly necessary to fulfill the relevant purposes. We regularly review contracts and other legal instruments entered into with third parties, including clients and suppliers, to ensure that they contain privacy and personal data protection provisions requiring such third parties to adopt technical and organizational measures designed to protect data handled in the course of the relevant legal relationship and permitting the Firm to inspect and audit compliance.

In addition, the Firm may share personal data as follows:

  • (i) In response to a request for information from a competent authority or third party, where we believe disclosure complies with any applicable law, regulation, or legal process;
  • (ii) With law-enforcement bodies, government authorities, or third parties, where strictly necessary to comply with due process of law and applicable legislation;
  • (iii) With companies providing document-archiving services;
  • (iv) With providers of translation services for our clients’ documents;
  • (v) With software and cloud-hosting service providers for registration, management, document issuance, and related purposes;
  • (vi) With providers of accounting services to the Firm;
  • (vii) With other law firms or independent attorneys that are our partners, or at our clients’ request;
  • (viii) In aggregated and/or anonymized form so that the information cannot be used to identify the data subject;
  • (ix) Where the data subject has been notified and authorizes the Firm to share his or her personal data;
  • (x) Any international transfer of personal data shall be made only to entities in countries that afford at least the same level of protection as the LGPD.

12. AUDITING AND MONITORING

TAGD periodically audits compliance with this Policy and shall implement corrective measures to remedy any irregularities.

13. RESPONSIBILITIES

TAGD’s responsibilities for processing the personal data described in this Policy are limited to its efforts to adopt best practices, pursuant to Article 32 of the LGPD.

14. COOKIES

Cookies are small text files stored on your device (computer, tablet, or mobile phone) that enable us to recognize your browsing preferences as an internet user and thereby improve your experience. We use cookies on our website to collect personal or browsing information for the purpose of improving your experience on each visit, by identifying the number of visits to the website and the geolocation of those visits through the IP address.

This Policy is effective as of May 29, 2022, at 19:12.

TAGD Advogados (Terciotti Andrade Gomes Donato Advogados) is a multidisciplinary business law firm with more than 10 years of experience, offices in São Paulo, Rio de Janeiro and Belém, and partners throughout Brazil and abroad. Our practice encompasses corporate law, tax, energy and dispute resolution, led by partners Maurício Terciotti, Daniel Andrade, Edgar Gomes and Raphael Donato. We combine the personal attention of a boutique firm with the agility of a modern practice, delivering tailored legal counsel through a pragmatic, business-oriented and results-focused approach.

IMPORTANT

CONTACT

Office Hours:
Sunday: Closed.
Monday: 09:00–19:00.
Tuesday: 09:00–19:00.
Wednesday: 09:00–19:00.
Thursday: 09:00–19:00.
Friday: 09:00–19:00.
Saturday: Closed.

Data Protection Officer (“DPO”): Patricia Barcellos
Deputy Data Protection Officer: Wagner Barros
Email: compliance@tagdlaw.com.br