Privacy Policy of the Portão 3 Platform
Last update: November 4, 2024.
1.DEFINITIONS
1.1. The capitalized terms used in this Privacy Policy have the meanings set forth below:
(i) “Cookies”: navigation files that temporarily store what the User is visiting on a particular website or application.
(ii) "Controller": individual or legal entity responsible for decisions regarding the processing of Personal Data.
(iii) “Independent Controllers”. two or more individuals or legal entities with decision-making power over the processing of Personal Data. Each Controller defines separately and independently the purposes and method of processing, each one responsible for the processing carried out in its sphere of activity.
(iv) “Personal Data”. Data identifying or making an individual identifiable.
(v) “Sensitive Personal Data”. Personal Data on racial or ethnic origin, religious belief, political opinion, trade union membership or organization of a religious, philosophical, or political nature, data on health or sexual life, genetic or biometric data, when associated with an individual.
(vi) "Anonymized Data". any data relating to a Subject that cannot be identified, considering the use of reasonable and available technical means at the time of their processing.
(vii) “Merchants” means any individual or legal entity that uses the Platform as a means of offering its products as accommodation, transportation options or other services designated to the Users.
(viii) “Personal Data Breach”. Information security breach that results in the accidental or unlawful destruction, loss, alteration, disclosure or unauthorized access of Personal Data transmitted, stored or otherwise processed by Portão 3 or an authorized subcontractor.
(ix) "Processor": individual or legal entity that processes Personal Data on behalf of the Controller.
(x) “Portão 3 Platform” or “Platform”. Virtual platform accessible via web or application, whose right of access and use is made available to Users in the "as a service" modality for the provision of the Services.
(xi) "Partner" is the payment institution that is part of the Brazilian Payment System (SPB), a partner of Portão 3, responsible for opening accounts and issuing cards, having the legal prerogatives to operate.
(xii) “User”. Any individual or legal entity who accesses the Portão 3 Platform from the adherence to the Terms of Use and this Privacy Policy, to request and buy the products and/or services offered by Portão 3.
2.WHAT DATA ARE PROCESSED?
2.1. When using the Platform, Users must provide some information for registration, use of the Platform and make requests. Some of these data are (i) provided directly by Users (such as registration and identification data, information entered by Users on the Platform, and information shared by Users when contacting us or interacting with other Users); (ii) provided indirectly by Users; and (iii) others provided to Us by third parties, always in accordance with applicable laws, as follows:
2.2. Periodically, Portão 3 may request the update of the Identification, Enrollment and Registration Data.
2.3. The User is the sole responsible for ensuring the accuracy, clarity, relevance and timely updating of the information provided, as necessary, and Portão 3 has no obligation to investigate the veracity of the information sent. The User acknowledges and agrees that inaccuracies, imprecisions or outdated information may impair or prevent the performance of requests through the Platform.2.4. Portão 3 does not collect information from persons under 18 years of age intentionally, unless there is prior consent of the minor's legal guardian, in which case the processing takes place for the purpose indicated in the consent obtained.
2.5. Portão 3, in the provision of the Platform and other services and accessory products, will act as a Controller of Personal Data processing. In relation to the Personal Data of Users that are processed by the Merchants or by the Partner, they will be considered as Independent Controllers of such Personal Data, assuming responsibility for the processing carried out by them using the Platform or outside of it. In this case, Portão 3, the Merchant, the Partner and the User will each be responsible for the processing of Personal Data carried out in their sphere of activity.
2.6. During the use of the Platform, the User might use other services, channels, products and platforms provided, maintained and/or operated by third parties, used as channels or means to support the services provided by Portão 3, but without any relation to Portão 3 (“Third Party Services”). Such Third Party Services may include communication and instant messaging applications. When Portão 3 services use such Third Party Services, the Personal Data processing will also be subject, in addition to this Privacy Policy, to the privacy policies and terms of use of such Third Party Services, under which Portão 3 has no control or interference. In this case, Portão 3 and such third party will be Independent Controllers of Personal Data,
3.FOR WHAT PURPOSE ARE THE DATA COLLECTED?
3.1. Portão 3 uses Users' Personal Data to provide the services requested by Users through the Portão 3 Platform, the main purposes of the Personal Data processing are:
(i) for the provision of the services, according to the Terms of Use linked to this Privacy Policy, including the products of travel management by the Platform, management of corporate expenses and also issuance of corporate cards.
(ii) through the Portão 3 User Service in order to inform the User of any request made. This includes service through the channels provided, as well as requests in general related to the Platform.
(iii) to communicate with the User via telephone, email, SMS, WhatsApp, Messenger, Instagram or any other messaging platform or social media about the operation of the Platform or a request made. Portão 3 and the Merchant may send messages to the User with information about the status of the request, summary of the request and its price, as well as offers, promotions, discount coupons or other communications for promotional or business purposes.
(iv) to generate aggregated, anonymous statistical analyses and reports on the performance and operation of the Platform and the services provided through the Platform, conduct satisfaction surveys on the Platform and the services provided by means of the Platform, investigate and analyze how to improve the services it offers to Users, as well as to develop and improve the characteristics of the Platform and the services it offers to Users, generate new products, business or market intelligence for Portão 3.
(v) to ensure security and an adequate environment to use the Platform and the safe provision of the services
(vi) to detect and investigate frauds, as well as other illegal activities and possible violations of this Privacy Policy, our Terms of Use and applicable laws. To this end, Portão 3 may share the User's Personal Data with partners who analyze fraud operations.
(vii) to send Users emails and promotional messages and/or offers related to the service supplied by Portão 3 or the Merchants, and that may be of interest to the User. If the Portão 3 User does not wish to receive the aforementioned information and/or commercial communications, it may at any time choose the option "Cancel the subscription" in the email itself and, consequently, the sending of said information will cease immediately.
(viii) Send emails about Platform updates, travel approval, information about corporate expenses paid and general information about the Platform.
(ix) to process payments and make charges related to the use of the Platform and the offer, request, contracting, supply and purchase of products and services, as provided for in the Terms of Use.
(x) to comply with its legal and/or regulatory obligations. These obligations may include, for example, tax and fiscal obligations, obligations on maintenance of technical records, documentation of contracted services, accountability, among others.
(xi) for Portão 3 to exercise its own rights and/or to defend its rights and interests before the User itself or third parties. This may include our-of-court negotiations between the Parties, court or arbitration proceedings, administrative proceedings, among others.
3.2. Other processing. In relation to the other Data processing carried out by Portão 3, these will be based on the following legal hypotheses, as applicable to each case: for performance of a contract or preliminary measures; for compliance with legal or regulatory obligations; for the exercise and defense of Portão 3 rights and interests; or based on a legitimate interest of Portão 3, always considering and respecting the fundamental rights and guarantees ensured to the Perssonal Data Subject; or further, based on the Consent, when expressly requested by the Platform.4.DOES PORTÃO 3 SHARE THE INFORMATION IT COLLECTS?
4.1. For the correct development of the contractual relationship and excellence in the provision of the service, as well as for its legitimate interest, Portão 3 may share certain Personal Data of Users, as follows:
(i) Merchants: the Portão 3 Platform mediates the relationship between Merchants that offer and sell their products and services and Users who wish to request and acquire such products or services from the Merchant through the use of the Portão 3 Platform.
(ii) Service providers: any outsourced service providers of Portão 3 (in case of outsourcing the service or solving incidents with the services) will have access to the Users' Personal Data necessary for the performance of their duties, but they cannot use them for other purposes.
(iii) Portão 3 Partner, for the purpose of opening the accounts and issuing the cards, according to applicable regulations;
(iv) Private security companies and public authorities and agencies: Portão 3 may disclose Users' Personal Data when it believes that its disclosure is necessary for compliance with the law, to enforce or apply the Terms and Conditions or this Privacy Policy, or to protect the rights, property or security of Portão 3, its Users or third parties;
(v) Upon legal requirement: Portão 3 may share information with public bodies and authorities and/or third parties regarding requests for information related to criminal investigations and alleged illegal activities or for the compliance with legal duties; (vi) Judicial or Administrative Request: Portão 3 may share Personal Data in case of judicial or administrative requests;
(vii) Compliance with legal or regulatory obligation: Portão 3 may share Personal Data with agencies, authorities and other government entities, as well as individuals or legal entities of a private nature, in compliance with legal or regulatory obligations;
(viii) Storage on Retool's servers (https://retool.com/) located in the United States of America. Portão 3 represents that said servers comply with the Data Protection Legislation and the commitments set forth in this Privacy Policy.
4.2. Sharing with Processors. Portão 3 may hire third parties to assist it in the provision of its services, such as cloud storage servers and payment processing platforms. At the moment, Portão 3 shares Users' Personal Data with infrastructure providers (servers, hosting and cloud services) for the proper functioning of the Platform, IT service providers, partners related to payment processing, but these suppliers can be replaced at any time, provided that adequate standards of data security and confidentiality are maintained. Portão 3, as a Controller of Personal Data, will require such Processor partners to provide adequate levels of security and confidentiality.
4.3. Sharing with Independent Controllers. In relation to Users' Personal Data that are processed by the Merchants, the Partner or Merchant's Personal Data that are processed by the Users for the offer, negotiation, request, contracting, acquisition and/or supply of products and services by the Merchants to the Users, Portão 3, the Merchant and the User will be considered Independent Controllers of such Personal Data, assuming responsibility for the processing carried out by them using the Platform or outside of it.
5.WHAT ARE USERS' RIGHTS?
5.1. Portão 3 provides tools for Users to exercise their legal rights over the Personal Data where they are Subjects. We will describe these rights in this section and how Users can exercise them.
(i) Confirmation of the existence of processing: Users can confirm that Portão 3 is processing their Personal Data;
(ii) Access to Personal Data: Users can access their Personal Data, including requesting a copy of the Data processed;
(iii) Correction of incomplete, inaccurate or outdated Data: Users may request changes or correction of their Personal Data that are incorrect;
(iv) Anonymization, temporary limitation or deletion: Users may request the anonymization, temporary limitation or deletion of unnecessary, excessive data, or which have been processed in non-compliance with the provisions of the Data Protection Legislation;
(v) Portability. Users may request the portability of their Data to another supplier as regulated by the applicable authorities;
(vi) Deletion of Personal Data. Users may request the deletion of their Personal Data processed by Portão 3 when they are collected and processed based on their consent, through the Platform itself or upon request through the service channels indicated in this Privacy Policy;
(vii) Information about sharing. Users can request information about with which public and private entities Portão 3 shared their Personal Data, under the terms of this Policy;
(viii) Revocation of consent. Users may revoke the consent previously provided for the processing of Personal Data at any time and at their discretion. The processing carried out based on it until such time remains valid.
5.2. Exercise of rights. The rights mentioned above and others provided for in the applicable legislation may be exercised by the Data Subject directly through the Platform, according to the functionalities made available therein (such as tools for accessing and editing Personal Data) or by means of a request addressed to the email oi@portao3.com.br. The requests must contain at least the name of the Data Subject, the right to be exercised, details and specifications about the request, CPF or CNPJ and the User's email address. Portão 3 reserves the right to request other information or documents to prove the applicant's allegations.
5.3. Data retention. Portão 3 may keep the Personal Data of certain Users for a period longer than that of legal custody, in compliance with any public authority orders, to defend itself in judicial and/or administrative proceedings and in cases where the Personal Data have been duly anonymized.
If the User requests the deletion of its information, but still has some obligation to meet towards Portão 3, its information will not be deleted and will remain stored in order to enable the solution of the pending issue and the adoption of appropriate measures.
6.HOW WE STORE PERSONAL DATA
6.1. Security. Portão 3 makes its best efforts to keep Personal Data always safe and even adopts technical and administrative security and protection measures compatible with the nature of the Personal Data collected, used, stored or otherwise processed by Portão 3, in accordance with appropriate market practices.
6.1.1. Exceptions. However, no method of transmitting or retaining electronic data is fully secure and may be subject to external attacks. Thus, Portão 3 cannot guarantee that such security measures are error-free or not subject to interference from third parties (hackers, among others). By its nature, despite Portão 3's best efforts, any security measure may fail and any Personal Data may become public.
6.1.2. In the event of a Security Breach on the Platform, the Subject and the Brazilian Data Protection Authority (ANPD) will be notified of the existence of such an incident, and Portão 3 will inform:
(i) The nature of the Personal Data affected;
(ii) Information about the Subjects involved;
(iii) The technical and security measures used to protect Personal Data, in view of trade and industrial secrets;
(iv) The risks related to the Incident;
(v) The measures that have been or will be taken to reverse or mitigate the effects of the damage.
6.1.3. The security measures described above apply to the User's Personal Data only from the moment Portão 3 receives it and while keeping it in its custody. The performance and security of the device that the User uses to access the Platform, as well as third-party networks through which the data travels, are not the responsibility of Portão 3.
6.2. International transfers. During all the time the User accesses, uses or maintains its account on the Portão 3 Platform active, all information collected will be stored with a high standard of security on its own servers, on servers operated and controlled by Portão 3, or even on third-party servers located in Brazil or abroad. The User is hereby informed that Portão 3 may store its Personal Data on servers outside Brazil and/or use service providers that are not in the Brazilian territory. In such cases, Portão 3 will comply with the legal requirements for such international transfers, ensuring the same level of security applied to processing carried out in Brazil.
6.3. Period of storage. The Personal Data will be retained for as long as necessary for the purposes listed in this Privacy Policy. This may mean, for example, that the Access Records will be stored for at least six (6) months, as required by law, or for a longer period, if so requested by the Personal Data Subject or determined by court order. Other Personal Data will be stored for the period of limitation of any civil liability, in order to allow the defense of Portão 3 in court, for example. Portão 3 adopts controls to ensure that the Personal Data is kept only while it is in fact necessary, being discarded whenever the processing is terminated or any legal hypothesis of retention does not apply.
6.4. Data deletion. When we no longer need to use the Personal Data, they will be removed from our systems and records or anonymized, so that the User can no longer be identified from that data. Portão 3 may retain certain Personal Data to comply with our legal or regulatory obligations, as well as to enable and ensure the regular exercise of our rights (e.g. in judicial, administrative or arbitration proceedings). For the purposes of auditing, security, fraud control and preservation of rights, Portão 3 may remain with the history of registration of the Personal Data for a longer period in the cases that the law or regulatory rules so establishes or to preserve rights.
6.5. Limitation of Liability. Nothing in the Privacy Policy is intended to exclude or limit any condition, warranty, right or liability that cannot be legally excluded or limited. Some jurisdictions do not allow the exclusion of certain warranties or conditions or the limitation or exclusion of liability for damages. Consequently, only such limitations as permitted by law in your jurisdiction apply to you. Where exclusion of liability is not possible, but the limitation of liability is legally applicable, the total liability of Portão 3 is limited to one thousand Brazilian Reals (BRL1,000.00).
7.RESPONSIBILITY OF THE USER IN THE PROTECTION OF ITS DATA
7.1. Although we keep the Personal Data confidential, in accordance with the terms of this Privacy Policy, it is responsibility of each User to keep the login and password of its account secure and not to provide them to any person.
7.2. If the User believes that its login and password to access its account on the Platform have been improperly accessed by third parties or are known to other unauthorized persons, for any reason, the User must immediately advise Portão 3 of it via email to oi@portao3.com.br, without prejudice to the prompt change of password through the Platform itself by the User.
8.COOKIES
8.1. Portão 3 uses Cookies and similar technologies such as pixels and tags to make sure that the services provided comply with our quality standards. Cookies only collect statistics, and are not used for purposes other than those expressly provided for in this Privacy Policy.
8.2. What are Cookies and what are they for? Cookie is a small file added to your device or computer to provide a customized experience when accessing the Platform. Portão 3 may use Cookies:
8.2.1. Required: Cookies that enable the use of the Platform and without which the Platform may not function properly. As such Cookies are required, they are used based on the performance of the agreement by and between Portão 3 and the User.
8.2.2. Functional: Cookies that enable additional functions or serve to make possible the access to certain specific sections of the Platform. The use of such Cookies is not absolutely necessary to use the service, but if you choose to disable them, the User may have reduced functionalities, so that the use of these Cookies is based on your consent when activating such functions.
8.2.3. Performance: Cookies used to measure and improve the performance of certain web pages and specific content contained on the page.
8.2.4. Social media: The Platform uses social media plugins, which allow you to access them from the Platform. Thus, by doing so, the Cookies used by them may be stored in the User's browser. Each social medium has its own privacy and personal data protection policy, and individuals or legal entities are responsible for the Personal Data collected and the privacy practices adopted. The User may search at the social media for information on how its Personal Data have been processed.
PORTÃO 3 DOES NOT HAVE ANY CONTROL OR INTERFERENCE ON SUCH THIRD PARTY WEBSITES, AND IS NOT RESPONSIBLE FOR THE CONTENTS, PRACTICES AND SERVICES OFFERED BY ANY THIRD PARTY, NOR FOR THE PROCESSING OF YOUR PERSONAL DATA BY SUCH WEBSITES AND SOCIAL MEDIA, EVEN WHEN THE LINKS ARE CONTAINED IN THE Portão 3 PLATFORM.
8.3. Is it possible to limit the use of Cookies? Browsers generally allow the collection of Cookies to be disabled, so if the User does not change the cookie collection policies of its browser, We will consider that the User is not against the use of Cookies by the Platform. Any collection of Personal Data identified by necessary Cookies is based on the need to provide the Platform (contract performance), while the implementation of the other Cookies, if it implies processing of identified Personal Data, is based on a legitimate interest of Portão 3. In the latter case, the User may object to such treatment by adjusting his browser settings to reject such Cookies.
9.CONTACT WITH PORTÃO 3
9.1. In case of questions, suggestions, complaints or clarifications about this Privacy Policy or the processing of Personal Data by Portão 3, or to request the exercise of any of the rights described in this Privacy Policy or in the Data Protection Legislation, the User may contact our Data Protection Officer, under the terms of the law, via the email: oi@portao3.com.br. Portão 3 will be pleased to answer any questions and/or meet your request.
10.UPDATES TO THE PRIVACY POLICY
10.1. Due to the continuous evolution of Portão 3 activities, this Privacy Policy and Terms of Use may be modified. Portão 3 will send the User notices of the substantial changes and modifications of said documents by email or any other means that guarantees their receipt. In any case, Portão 3 will in no event modify the policies or practices to make them less effective in protecting our Users' previously stored Personal Data. The User should check this page and review this Privacy Policy from time to time to ensure that it agrees with such modifications.
10.2. Except when express consent is required, if the User continues to use the Platform and/or does not object to the changes and new terms informed by Portão 3 after the disclosure of the new version of the Privacy Policy, it will be understood that the User is fully aware of and agrees with the new terms applicable to the Personal Data processing. If the User does not agree with the changes to the Privacy Policy, it must refrain from using the Platform and may request the cancellation of its account, in accordance with the Terms of Use.