Privacy Policy
Last updated: June 2026
This policy describes how Passos Consultoria collects, uses and protects your personal data, in compliance with the Brazilian General Data Protection Law (LGPD).
Last updated: June 22, 2026
This Privacy Policy ("Policy") transparently describes how our Organization collects, stores, uses, shares and protects the personal data of its clients, employees, partners and website users, in strict compliance with the Brazilian General Data Protection Law (Law No. 13.709/2018 — LGPD) and other applicable legislation.
1. Scope and Data Collected
Section 1.1 — Data Provided Directly by the Data Subject
We collect information that is essential to delivering our services and improving your professional experience with us. This data includes, but is not limited to:
- Identifying data: full name, taxpayer ID, identity document, date of birth.
- Contact information: e-mail address, phone number and residential/business address.
- Financial data: payment information, banking data and transaction history required for corporate billing.
Section 1.2 — Data Collected Automatically
For information security, internal auditing and compliance with legal obligations, our servers record technical browsing data:
- IP address, browser type, operating system, approximate geolocation and history of interactions with our digital platform through cookies and equivalent identifiers.
2. Purpose and Legal Bases for Processing
Section 2.1 — Institutional and Commercial Purpose
In line with Article 6 of the LGPD (Purpose Principle), data processing is intended to:
- Perform service agreements or terms of use accepted by the user;
- Manage customer service, technical support and the processing of financial requests;
- Communicate security updates, important corporate notices and personalized marketing (subject to the right to opt out).
Section 2.2 — Legal Grounds
We ensure that all personal data processing is supported by a legitimate legal basis, such as:
- Performance of a contract: necessary to fulfill the established relationship.
- Legitimate interest: to develop and protect our operational activities, provided they do not override the data subject's fundamental rights.
- Compliance with a legal/regulatory obligation: storage of digital records required by regulators or tax law.
- Consent: collected expressly and prominently for specific, ancillary purposes.
3. Sharing and International Data Transfer
Section 3.1 — Sharing with Third Parties
The Organization restricts access to personal data only to business partners and service providers strictly necessary to operations (e.g., cloud infrastructure providers, payment gateways and external auditors). All third parties are contractually bound to maintain strict confidentiality and security levels equivalent to our standards.
Section 3.2 — International Transfer
Where data is stored on servers located outside the national territory, we ensure that the receiving country or international entity provides an adequate level of protection, using contractual safeguards such as Standard Contractual Clauses.
4. Information Security and Data Retention
Section 4.1 — Technical and Administrative Protection Measures
We adopt strict information governance and security measures to shield data against unauthorized access, leakage or accidental destruction. Corporate safeguards include encryption of data at rest and in transit, strict access control for employees and periodic vulnerability audits.
Section 4.2 — Retention Periods
Personal data is kept only for the period necessary to fulfill the purposes described in this Policy, or as required by applicable statutory limitation periods for the corporation's legal defense.
5. Data Subject Rights and DPO Contact
Section 5.1 — Exercising Rights Guaranteed by the LGPD
Any data subject may request, at any time and free of charge, through our official channel:
- Confirmation that processing exists and access to the stored data;
- Correction of incomplete, inaccurate or outdated information;
- Anonymization, blocking or deletion of unnecessary data or data processed in non-compliance;
- Withdrawal of previously granted consent.
Section 5.2 — Official Communication Channel (Data Protection Officer / DPO)
For legal questions or privacy requests, contact our Data Protection Officer (DPO) directly through the standard service address of the privacy portal.
If you prefer, you may consult the regulatory guidelines and the legal source document directly in our repository of original documents or on the government website.
Access the original source text (LGPD regulatory source)
