Privacy Policy

POL-12 Privacy Policy Rev.01

This Policy sets out the guidelines adopted by Voidr for the processing of Personal Data, ensuring it is carried out lawfully, transparently and securely, in compliance with Applicable Law and with the controls set out in the ISO/IEC 27001 standards.

Version Control

VersionDatePrepared byApproved byContent
002026-04-13NathaliaMilsonInitial release of the document
012026-05-14NathaliaMilsonRestructuring and alignment

1. Purpose

This Policy sets out the guidelines adopted by Voidr for the processing of Personal Data, ensuring it is carried out lawfully, transparently and securely, in compliance with Applicable Law and with the controls set out in the ISO/IEC 27001 standards.

The purposes of this Policy are to:

  • (i) Guide Employees, partners and suppliers on Personal Data processing practices;
  • (ii) Ensure compliance with the purposes for which the data was collected;
  • (iii) Safeguard the rights of Data Subjects and the procedures for exercising them.

2. Scope

This Policy must be observed by all Employees, across every area of Voidr that may have access to information, systems and Personal Data processed by Voidr.

It applies to all Personal Data processing activities carried out by Voidr, including:

  • Data of Users and Customers who interact with the websites, applications and testing platform;
  • Data of Employees, partners, service providers and suppliers;
  • Cloud environments and third-party systems that process data on behalf of Voidr.

This Policy must be observed together with the Information Security Policy and the Retention and Disposal Policy (POL-04).

3. Definitions

  • "Employee": any person professionally involved with Voidr, including partners, directors, staff, interns, service providers and business partners.
  • "Controller": the natural or legal person responsible for decisions regarding the processing of Personal Data.
  • "Personal Data": information relating to an identified or identifiable natural person.
  • "Sensitive Personal Data": data concerning racial or ethnic origin, religious belief, political opinion, trade union membership, health, sex life, or genetic or biometric data.
  • "Data Protection Officer (DPO)": the professional appointed by Voidr to act as the communication channel between the company, Data Subjects and the ANPD (Brazilian Data Protection Authority).
  • "Processor": the natural or legal person who processes Personal Data on behalf of the Controller.
  • "Data Subject": the natural person to whom the Personal Data relates.
  • "Processing": any operation carried out with Personal Data, such as collection, storage, use, sharing and deletion.

4. Responsibilities

  • Senior Management: Approve this Policy and its revisions, ensure the resources required for its implementation, and be informed of relevant incidents and non-conformities.
  • Data Protection Officer (DPO): Keep this Policy up to date, receive and respond to Data Subject requests, act as the communication channel with the ANPD, lead the response to incidents involving Personal Data, and periodically audit compliance with this Policy.
  • IT Department: Implement and maintain the technical controls protecting Personal Data, including encryption, access control, audit logs and backup.
  • Legal Support: Validate the legal bases for processing, review privacy clauses in supplier contracts, and advise the DPO on judicial or administrative matters.
  • Employees: Comply with this Policy, process Personal Data only within the limits of their duties, and immediately report any suspected incident to the DPO.

5. Collection and Purposes of Processing

Voidr collects Personal Data directly from Data Subjects (through forms, registrations and interactions on its platforms) and automatically (usage, device and telemetry data). Where applicable, it may also receive data from public sources or partners.

Personal Data is used to:

  • Provide and improve the services, including account creation, support and transaction processing;
  • Communicate with Data Subjects and, where authorised, send marketing communications;
  • Comply with legal, regulatory and contractual obligations;
  • Ensure security, prevent fraud and monitor incidents.

Each processing activity will be carried out on one of the legal bases set out in the LGPD (Brazilian General Data Protection Law), according to the data category and the purpose.

6. Acting as Controller and as Processor

Voidr acts as Controller in relation to the Personal Data of its Employees, corporate customers and users of its commercial platforms.

Voidr acts as Processor in relation to Personal Data processed on behalf of its customers in the performance of contracted services, following the Controller's instructions as to purpose, retention periods and other processing conditions. In self-hosted mode, the data remains entirely within the customer's infrastructure.

7. Sharing and International Transfer

Voidr may share Personal Data with:

  • Authorised Employees, strictly for the performance of their duties;
  • Service providers and suppliers, under contracts containing data protection, confidentiality and security clauses;
  • Regulatory authorities and public bodies, where required by law or judicial decision;
  • Business partners, subject to the applicable legal bases.

International transfers will only be carried out with adequate safeguards in place, such as Standard Contractual Clauses, pursuant to article 33 of the LGPD.

8. Rights of Data Subjects

In accordance with the LGPD, Data Subjects have the right to:

  • Confirmation that processing exists, and access to the data;
  • Correction of incomplete, inaccurate or outdated data;
  • Anonymisation, blocking or deletion of unnecessary data or data processed in breach of the law;
  • Data portability;
  • Information about the sharing of their data;
  • Withdrawal of consent;
  • Objection to processing, particularly for direct marketing.

Requests must be submitted to the DPO and answered within 15 (fifteen) calendar days, unless specific legislation sets a different deadline. Where Voidr acts as Processor, requests are forwarded to the Controller, with the support necessary to fulfil them.

9. Information Security

Voidr adopts technical and administrative measures to protect Personal Data against unauthorised access, loss, alteration or improper processing, including:

  • Encryption of data at rest and in transit, with support for customer-managed keys where contractually agreed;
  • Access controls based on multi-factor authentication (MFA), with SSO support;
  • Audit logs of access to and modification of Personal Data;
  • Backup and recovery procedures;
  • Automatic anonymisation in logs and reports;
  • Mandatory periodic training for Employees.

10. Retention and Disposal

Retention periods and disposal procedures for Personal Data follow the Retention and Disposal Policy (POL-04). Once the retention period ends or the purpose of processing has been achieved, Personal Data will be securely deleted or irreversibly anonymised.

11. Personal Data Incidents

Any Employee who becomes aware of a security incident involving Personal Data must immediately notify the DPO through the channels listed in item 13.

The DPO will lead the investigation and, depending on severity, will notify the ANPD, the affected Data Subjects and, where Voidr acts as Processor, the relevant Controller, within the deadlines and in the manner set out in the applicable regulations.

12. Term

This Policy takes effect on the date of its publication, for an indefinite term, and may be amended by Voidr at any time, subject to the version control process set out in item 3.

This Policy must be reviewed at least annually, or whenever there are relevant changes to data processing activities, to applicable legislation, or as a result of internal and external audits.

13. Distribution, Communication and Control

A copy of this Policy will be made available through Voidr's Google Drive and on the Official Website, controlled in accordance with the Master List, following notification of additions and changes by email to the Employees involved.

For clarifications, requests or to exercise your rights, please contact Voidr's Data Protection Officer:

DPO: Fabiano Kenzo

Deputy DPO: Nathalia

Address: São Paulo, SP, Brazil

If a satisfactory response is not received, the Data Subject may escalate the matter to the ANPD (Brazilian National Data Protection Authority).