In compliance with the General Personal Data Protection Law — Law No. 13,709/2018 (LGPD)

May/2025 Effective Date: 06/01/2025 Approved by the DPO

1. Presentation and Commitment

Belasis (belasis.com.br) — hereinafter referred to simply as "Belasis", "we", or the "Company" — has developed this Privacy and Personal Data Protection Policy to demonstrate its irrevocable commitment to the privacy, transparency, and security of the information of everyone who interacts with its products, services, and digital platforms.

This document establishes, in a clear and objective manner, how we collect, use, store, share, and protect the personal data of clients, users, partners, suppliers, and collaborators, in full compliance with:

  • General Personal Data Protection Law — LGPD (Law No. 13,709/2018) and its regulations;

  • Brazilian Civil Framework of the Internet (Law No. 12,965/2014);

  • Consumer Defense Code (Law No. 8,078/1990);

  • General Data Protection Regulation of the European Union — GDPR (Regulation EU 2016/679), when applicable;

  • Rules and guidelines issued by the National Data Protection Authority — ANPD.

Principles that guide our actions

Every data processing operation carried out by Belasis complies with the principles of

purpose, adequacy, necessity, free access, data quality, transparency, security, prevention, non-discrimination, and accountability

— provided for in Article 6 of the LGPD.

2. Controller, Processor, and Officer (DPO)

2.1 Identification of the Controller

Corporate Name

Belasis Tecnologia Ltda.

Website

www.belasis.com.br

Privacy E-mail

privacidade@belasis.com.br

Belasis acts as the Controller of the personal data it collects directly from its users and clients, being responsible for decisions regarding the purposes and means of processing this data, as defined in Article 5, VI of the LGPD.

2.2 Data Protection Officer (DPO)

In compliance with Article 41 of the LGPD, Belasis has designated a Data Protection Officer (DPO), whose duties include:

  • Accepting complaints and communications from data subjects and providing clarifications;

  • Receiving communications from the National Data Protection Authority (ANPD);

  • Guiding employees and contractors on data protection practices;

  • Executing other duties determined by the Controller or established in complementary standards.

Contact the DPO: dpo@belasis.com.br

3. Personal Data Collected

3.1 Categories of Data

Belasis collects only the data strictly necessary for the declared purposes (principle of minimization). The categories of processed data are:

Category

Examples of Data

Identification

Full name, CPF/CNPJ, RG, date of birth, gender, profile photo

Contact

E-mail, telephone, full address, ZIP code

Access and Authentication

Login, encrypted password (hash), session tokens, MFA, access history

Platform Use

Pages visited, features used, activity logs, session time

Device

IP address, browser type, operating system, device identifier

Financial

Credit/debit card data (tokenized via gateway), transaction history

Communication

Messages exchanged with support, e-mails, chat, service records

Location

Approximate geolocation (only when expressly authorized)

Professional

Job title, company, area of activity (for corporate users)

3.2 Sensitive Data

Belasis, as a rule, does not request sensitive personal data (as defined in Article 5, II of the LGPD). If, in specific services, the processing of such data is necessary, we will obtain specific and highlighted consent from the data subject, as required by Article 11 of the LGPD.

3.3 Minors' Data

Belasis does not intentionally collect data from children (under 12 years of age). When data from adolescents (12 to 18 years of age) is collected, it will be done with the consent of at least one parent or legal guardian, pursuant to Article 14 of the LGPD, and always in the best interest of the minor.

4. Purposes and Legal Bases of Processing

Every data processing operation carried out by Belasis has a legitimate, specific purpose informed to the data subject, supported by at least one of the legal bases provided for in Articles 7 and 11 of the LGPD:

Purpose

Legal Basis (LGPD)

User account creation and management

Execution of contract (Art. 7, V)

Provision of contracted services

Execution of contract (Art. 7, V)

Transactional communications (invoice, receipt, alerts)

Execution of contract (Art. 7, V)

Customer support and service

Contract / Legitimate interest (Art. 7, V and IX)

Sending marketing communications and updates

Consent (Art. 7, I)

Usage analysis, UX, and product improvement

Legitimate interest (Art. 7, IX)

Fraud prevention and platform security

Legitimate interest / Legal obligation (Art. 7, VI and IX)

Compliance with tax and accounting obligations

Legal or regulatory obligation (Art. 7, II)

Regular exercise of rights in legal proceedings

Regular exercise of rights (Art. 7, VI)

Satisfaction surveys and NPS

Consent / Legitimate interest

Experience customization and recommendations

Consent / Legitimate interest (Art. 7, I and IX)

5. How We Collect Data

Personal data is collected through the following means:

  • Directly from the data subject: registration, forms, checkout, contact with support, surveys;

  • Automatically: cookies, tracking pixels, server logs, and analysis SDKs;

  • By third parties: integrations authorized by the data subject themselves (social login, partner APIs);

  • Public sources: data available in public registries, when necessary for identity verification or compliance.

5.1 Cookies and Tracking Technologies

Belasis uses cookies and similar technologies to ensure the platform's operation, customize the user experience, and collect performance metrics. Cookies are classified as:

  • Strictly necessary: indispensable for the basic operation of the platform. They cannot be deactivated.

  • Functional: remember user preferences (language, layout). They can be deactivated without critical impact.

  • Analytical / Performance: collect usage data. They require consent.

  • Marketing and advertising: used to display relevant content. Always subject to explicit consent.

Users can manage their cookie preferences at any time through the Privacy Panel available on our website or through their browser settings.

6. Data Sharing with Third Parties

Belasis does not sell personal data. Sharing occurs exclusively in the situations below, always with contractual protection guarantees equivalent to those in this Policy.

Recipient / Category

Purpose and Conditions

Payment processors (e.g., Stripe, PagSeguro, Mercado Pago)

Secure processing of financial transactions. Tokenized data only.

Cloud infrastructure providers (AWS, Google Cloud, Azure)

Hosting, processing, and storage. Subject to DPA (Data Processing Agreement).

Analytical tools (e.g., Google Analytics, Mixpanel)

Behavior and performance analysis. Pseudo-anonymized data.

CRM and support platforms (e.g., HubSpot, Zendesk, Intercom)

Customer relationship management. Restricted and controlled access.

Transactional e-mail providers (e.g., SendGrid, Amazon SES)

Sending notifications and communications.

Authorized integration partners

When the data subject expressly authorizes integration via OAuth or similar.

Public authorities and regulators

Compliance with court orders or legal obligations. Minimum necessary.

Law firms and auditors

Regular exercise of rights in legal processes, subject to NDA.

International Data Transfer

When personal data is transferred to other countries or international organizations, Belasis adopts the safeguards required by Article 33 of the LGPD and Article 46 of the GDPR:

standard contractual clauses (SCCs)

, adherence to adequacy programs recognized by the ANPD/European Commission, or obtaining specific consent from the data subject. All of our international providers are evaluated for the adequacy of their data protection practices prior to contracting.

7. Security: OF the Cloud vs. IN the Cloud

Protecting data hosted in cloud computing environments requires understanding a fundamental concept adopted by all major global providers — Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform: the Shared Responsibility Model.

7.1 The Shared Responsibility Model

As extensively documented by AWS in its Security Center and recognized by the industry, there is a critical and often misunderstood distinction between two security domains:

Security OF the Cloud — Responsibility of the Provider

It is the provider's responsibility (AWS, Azure, GCP) to protect the physical infrastructure that runs all services: data centers, network, hardware, virtualization, and hypervisors.

The provider ensures that the data center is not physically breached and that servers do not fail due to external causes.

Security IN the Cloud — Responsibility of Belasis

It is Belasis's responsibility to protect everything it places and runs in the cloud: user data, applications, identity and access, network configurations, and encryption.

Belasis ensures that data is encrypted, accessible only to authorized personnel, and protected against logical threats.

7.2 Technical and Organizational Measures of Belasis

Within the scope of security IN the cloud — the direct responsibility of Belasis —, we adopt the following measures, aligned with international best practices (NIST CSF, ISO 27001, CIS Controls, SOC 2 Type II):

Encryption

  • Encryption at rest: all stored personal data is encrypted with AES-256;

  • Encryption in transit: all communication between client and server uses TLS 1.2 or higher (mandatory HTTPS);

  • Passwords stored exclusively as an irreversible hash (bcrypt or Argon2) with a unique salt per user;

  • Cryptographic keys managed in dedicated KMS (Key Management Service) services with periodic automatic rotation.

Access Control

  • Principle of least privilege: employees and systems access only what is strictly necessary for their roles;

  • Mandatory Multi-Factor Authentication (MFA) for all administrative access and critical systems;

  • Periodic review of permissions and access (quarterly Access Review);

  • Strict segregation of environments: production, staging, and development are completely isolated.

Monitoring and Detection

  • Access logs and events stored for at least 3 months and monitored in real-time;

  • Intrusion detection system (IDS/IPS) and SIEM for correlation of security events;

  • Automatic alerts for atypical access, brute force attempts, and possible data exfiltration;

  • Bug Bounty Program for responsible vulnerability reporting by security researchers.

Continuity and Resilience

  • Automatic daily backups with 30-day retention;

  • Multi-region architecture to ensure availability;

  • Disaster Recovery Plan (DRP) and Business Continuity Plan (BCP) reviewed annually;

Security in Development (DevSecOps)

  • Secure Software Development Lifecycle (SSDLC) practices: code review, static analysis (SAST), and dynamic analysis (DAST);

  • Vulnerability management policy with remediation SLAs based on criticality (CVSS Score);

  • Management of third-party dependencies and continuous verification of CVEs in libraries used.

7.3 Your Responsibility as a User

The Shared Responsibility Model does not end with the relationship between Belasis and its infrastructure providers. It extends to you, the data subject and platform user. The security of your account depends, in significant part, on the practices you adopt in your daily digital routine.

No matter how robust the security we implement in our infrastructure is, no technical measure is capable of protecting an account whose access was compromised due to user oversight. The main threats affecting accounts on SaaS platforms — phishing, credential stuffing, session hijacking — exploit human behavior, not system flaws.

Below are the practices we strongly recommend to all Belasis users:

Credentials and Authentication

  • Never share your password with other people, including coworkers, family members, or anyone identifying themselves as the Belasis support team. Our team will never ask for your password.

  • Use strong and unique passwords: at least 12 characters, combining uppercase and lowercase letters, numbers, and symbols. Avoid birth dates, first names, or predictable sequences.

  • Do not reuse passwords across different services. If a third-party platform suffers a breach, reused credentials put all your other accounts at risk.

  • Use a password manager (e.g., Bitwarden, 1Password, Dashlane) to create and store unique and complex passwords without needing to memorize them.

  • Change your password immediately if you suspect it has been exposed, that another account with the same password has been compromised, or that someone has had unauthorized access to your device.

Devices and Access Environments

  • Avoid accessing your account from public computers — internet cafes, libraries, hotel lobbies, airport terminals. These environments frequently have keyloggers, installed malware, or configurations that retain session data.

  • Avoid open public Wi-Fi networks without protection (malls, airports, coffee shops). If necessary, use a trusted VPN to encrypt traffic before accessing the platform.

  • Keep your devices updated: operating systems, browsers, and applications with pending updates are frequent vectors of exploitation. Apply security patches regularly.

  • Install software only from trusted sources and keep an active antivirus/antimalware on your personal and professional devices.

  • Lock your device with a password, PIN, or biometrics. In case of loss or theft, end your session remotely via the account dashboard and contact our support immediately.

Session Management

  • Always log out when you finish using the platform, especially on shared or third-party devices.

  • Review connected devices to your account periodically and end unknown or inactive sessions through the settings panel.

  • Do not remain logged in indefinitely on devices that other people can physically access.

Awareness of Scams and Social Engineering

  • Be suspicious of e-mails, SMS, or messages requesting your credentials, asking to click on urgent links, or simulating official Belasis communications. Always verify the sender and access the platform by typing the address directly into the browser.

  • Belasis will never ask for your password via e-mail, chat, or phone. Any message with this content should be treated as a phishing attempt and reported to privacidade@belasis.com.br.

  • Always verify the web address (URL) before entering your credentials. Make sure the address is exactly belasis.com.br and that the connection is secure (HTTPS padlock).

  • Beware of browser extensions that request broad access to visited pages. Malicious extensions can capture form fields, including passwords.

Corporate Access and Teams

  • Each user must have their own individual access. Sharing accounts among employees compromises the traceability of actions and violates the principle of accountability.

  • Revoke access immediately when an employee leaves the company or changes roles. The account administrator is responsible for keeping permissions always up to date.

  • Apply the principle of least privilege: grant each user only the permissions strictly necessary for their tasks. Administrative access should be restricted to the bare minimum.

Report any suspicion

If you identify suspicious activity on your account, receive a communication that appears fraudulent, or suspect your credentials have been compromised, contact our security team immediately at privacidade@belasis.com.br. The faster the report, the greater our ability to mitigate the impact.

8. Rights of Data Subjects

Belasis respects and guarantees the full exercise of all data subject rights provided for in Article 18 of the LGPD:

Right (Art. 18, LGPD)

Description and Term

Correction (III)

Request updates to incomplete, inaccurate, or outdated data.

Anonymization, Blocking, or Elimination (IV)

Request the anonymization or elimination of unnecessary data or data processed in non-compliance with the LGPD.

Portability (V)

Receive your data in a structured and interoperable format (JSON, CSV, XLS), except for already anonymized data.

Elimination based on consent (VI)

Request the elimination of data processed based on consent, subject to legal retention hypotheses.

Revocation of consent (IX)

Revoke given consent, without prejudice to processing carried out before the revocation.

Complaint to the ANPD (§1º)

Petition the National Data Protection Authority in case of violation of this Law.

How to exercise your rights

Send your request to privacidade@belasis.com.br or use the form available at belasis.com.br/privacidade. We will verify your identity before processing sensitive requests. The standard response time is 15 business days, which may be extended with a reasoned justification.

9. Data Retention and Disposal

Personal data is kept only for the time necessary to fulfill the purposes for which it was collected, observing minimum legal retention periods. After the retention period ends, the data is securely disposed of (secure overwrite / cryptographic deletion) or irreversibly anonymized.

Data Type

Retention Period

Active account data

For the duration of the account + 5 years after closure

Tax and billing data

10 years (Art. 195 of the CTN)

Access logs (Brazilian Civil Framework of the Internet)

6 months (Art. 15 of Law No. 12,965/2014)

Platform activity logs

12 months for security and support purposes

Consent data and preferences

As long as consent is valid + 5 years for proof purposes

Support and customer service recordings

90 days, unless used in court/administrative proceedings

Marketing and communication data

Until revocation of consent or opt-out


9.1 Data Retention After Subscription Termination

Upon terminating your subscription with Belasis — whether through voluntary cancellation, non-renewal, or contractual termination —, the rules described below regarding storage, access, and deletion of your data apply. We recommend reading this carefully before confirming any cancellation.

Export your data before canceling

During your active subscription period, you have access to export tools that allow you to download all your data in structured and portable formats. It is your responsibility to export any information you wish to keep before confirming the cancellation. Belasis provides this export functionality and recommends that this step be completed in advance, without waiting for the final days of the subscription.

Attention before canceling: after subscription termination, access to the platform interface is suspended. Data not previously exported can only be accessed by reactivating the subscription, as described below.

Account freezing period (90 days)

After the subscription ends, your account enters a frozen state for a period of 90 (ninety) calendar days, starting from the end of the contract validity. During this period:

  • Access to the platform and all stored data is suspended;

  • Data remains stored with the same security standards applied to active accounts;

  • No processing operation is performed on the data other than secure storage;

  • There is no charge for maintaining the account in a frozen state during this period.

Accessing data during the freeze

If you wish to access your data during the freezing period, you will need to reactivate the subscription. Simply freezing the account does not guarantee access to the interface or the platform's features. Reactivation can be requested at any time within the 90 days via the self-service portal.

Belasis remains responsible for the security and integrity of the stored data throughout the freezing period, regardless of subscription status. Temporary storage does not imply any use of the data for purposes other than those provided for in this Policy.

Data deletion at the end of the freezing period

After the 90-day freezing period has elapsed without subscription reactivation, account data will be permanently and irreversibly deleted from all Belasis systems, including operational backups, within a technical timeframe of up to 30 additional days after the end of the freezing period.

Once deleted, it will not be possible to retrieve any information associated with the account, regardless of subsequent reactivation or legal request, except in cases where Belasis is required by law to maintain specific records (see retention table in Section 9).

Exceptions for extending the retention period

The standard 90-day period may be extended by Belasis exclusively in the following situations, all with express legal basis:

  • Legal or regulatory obligation: when applicable law (tax, labor, accounting, or sector-specific) requires the retention of records for a longer period;

  • Ongoing judicial, administrative, or arbitral proceedings: when the data is relevant to the defense of rights in a dispute involving Belasis or the data subject themselves;

  • Fraud investigation or security incident: when there is evidence of account misuse or suspicious activity that justifies temporary preservation of evidence;

  • Express request of the data subject: when the user themselves formally requests the extension of the retention period for justified reasons.

Under no circumstances will data be retained beyond what is strictly necessary for the purpose that justified the extension. The data subject will be informed of the extension and its motivation whenever possible.

Prior notice before deletion

Belasis will send a notice by e-mail 15 days in advance before the final deletion of data, to the address registered on the account. If there is no interest in reactivating the subscription, no action is required. If you wish to regain access, the notice will serve as the last opportunity for reactivation before irreversible deletion.


10. Security Incidents and Breach Response

Belasis maintains a structured Incident Response Plan (IRP), inspired by the best practices of NIST SP 800-61 and aligned with the obligations of Article 48 of the LGPD and Article 33 of the GDPR. In case of an incident that may result in relevant risk or damage to data subjects, we will adopt the following steps:

  • Detection and analysis: Identification of the scope, nature of the affected data, and risk potential for the data subjects.

  • Immediate containment: Isolation of the attack vector and mitigation to prevent propagation and worsening.

  • Notification to the ANPD: Within 72 hours from becoming aware of the incident, when there is a relevant risk or damage (Art. 48, §1º of the LGPD).

  • Communication to affected data subjects: Within a reasonable timeframe, with clear information about the nature of the incident, affected data, measures adopted, and self-protection guidelines.

  • Post-incident: Root-cause analysis, lessons learned, and implementation of documented preventive improvements.

Belasis documents all incidents in an internal log, including those evaluated as non-reportable, for the purposes of demonstrating compliance (accountability).

11. Detailed Cookie Policy

Tool / Cookie

Purpose and Control

Google Analytics (_ga, _gid)

Audience and behavior analysis. Anonymized data. Can be deactivated via opt-out.

Hotjar (hjid, hjsv)

Heatmaps and session recording. No direct identification data. Opt-out available.

Crisp.chat (crisp_id)

Real-time customer support chat. Conversation data stored on Crisp's servers. Opt-out possible without loss of critical functionality.

Asaas (_asaas_tracking)

Billing processing, subscriptions, and financial anti-fraud. Strictly necessary for transactions. Cannot be deactivated.

Authenticated session (belasis_session)

Keep user logged in. Strictly necessary. Expires after inactivity.

12. International Data Transfer

Some of our technology providers have operations outside Brazil. In these cases, we adopt the following safeguards:

  • Standard Contractual Clauses (SCCs): contracts with specific data protection clauses approved by the competent authorities (ANPD/EC);

  • Adequacy Decisions: preference for countries recognized as adequate by the ANPD or the European Commission;

  • Data Processing Agreements (DPAs): bilateral agreements with all international processors, establishing obligations, audit rights, and sanctions;

  • Binding Corporate Rules (BCR): adoption of BCRs when applicable to multinational business groups.

The main countries involved include the United States (AWS, Google, Stripe), European Union (failover servers), and Brazil (headquarters and main processing). All transfer agreements are available for consultation upon request to the DPO.

13. Privacy by Design and Privacy by Default

Belasis adopts the principles of Privacy by Design and Privacy by Default as a fundamental philosophy in product and service development:

13.1 Privacy by Design — 7 Foundational Principles

  • Proactive, not reactive: anticipate and prevent privacy risks before they occur;

  • Privacy as the default setting: the most restrictive settings are automatically applied;

  • Privacy embedded into design: integrated from the start, not added as a later layer;

  • Full functionality: privacy without compromising functionality (no false dichotomy);

  • End-to-end security: protection throughout the entire data lifecycle;

  • Visibility and transparency: auditable operations open to verification;

  • Respect for the user: keeping privacy centered on the data subject.

13.2 Privacy by Default in Practice

  • Optional profile fields disabled by default;

  • Marketing notifications disabled upon account creation (require active opt-in);

  • Sharing with analytical third parties requires explicit consent;

  • Sessions automatically expire after a period of inactivity;

  • Profile visibility set to private by default.

14. Compliance and Governance Program

Belasis maintains an ongoing compliance program with the LGPD, structured on the following pillars:

  • Data Mapping: updated inventory of all processing flows, processors involved, and applicable legal bases;

  • RIPD — Data Protection Impact Assessment: prepared for high-risk processing, pursuant to Article 38 of the LGPD and ANPD guidelines;

  • Regular training: continuous training program for all employees who handle personal data;

  • Supplier Due Diligence: privacy and security evaluation of all processors before hiring and periodically;

  • Internal and external audits: annual reviews of compliance with the LGPD, GDPR, and other applicable regulations;

  • Whistleblowing Channel: confidential channel for reporting violations of the privacy policy by employees or third parties.

15. General Provisions

15.1 Amendments to this Policy

This Policy may be updated periodically to reflect legal, regulatory, technological, or operational changes. We will notify data subjects of significant changes by e-mail (for registered users). The current version will always be available at belasis.com.br/legal/lgpd.

15.2 Applicable Law and Venue

This Policy is governed by the laws of the Federative Republic of Brazil. In case of disputes regarding personal data protection, the parties elect the Jurisdiction of the District of Chapecó/SC, unless otherwise provided by law. The parties may also appeal to the National Data Protection Authority (ANPD) to resolve matters concerning compliance with the LGPD.

15.3 Glossary

Term

Definition

Personal Data

Information related to an identified or identifiable natural person (Art. 5, I, LGPD)

Sensitive Data

Data on racial/ethnic origin, religious belief, health, sexual life, genetic data, etc. (Art. 5, II)

Controller

Person who decides the purposes and means of data processing (Art. 5, VI)

Processor

Person who performs data processing on behalf of the controller (Art. 5, VII)

Data Subject

Natural person to whom the processed personal data refers (Art. 5, V)

Processing

Every operation carried out with personal data: collection, production, access, transmission, elimination, etc.

Consent

Free, informed, and unequivocal expression by the data subject (Art. 5, XII)

Anonymization

Process through which data loses the possibility of direct or indirect association with an individual

ANPD

National Data Protection Authority — regulatory and supervisory body of the LGPD in Brazil

DPO

Data Protection Officer — Person in charge of personal data processing (Art. 41 of the LGPD)

GDPR

General Data Protection Regulation of the European Union — Regulation (EU) 2016/679

KMS

Key Management Service — Centralized management service for cryptographic keys

SCC

Standard Contractual Clauses — Standard Contractual Clauses for international data transfer

DPA

Data Processing Agreement — Data Processing Agreement signed with processors

15.4 Contact Channels

Belasis — Privacy Channel

General privacy e-mail: privacidade@belasis.com.br

DPO e-mail: dpo@belasis.com.br

Privacy Portal: belasis.com.br/legal/lgpd

National Data Protection Authority (ANPD): gov.br/anpd

This document was drafted based on Law No. 13,709/2018 (LGPD), the GDPR, and the best practices of the global SaaS market.