Third Party Index

Snapshot 37186

Document
Privacy policy
URL
https://aktienow.com/en/privacy-and-data-protection-policy/
Fetched
HTTP status
200
Content type
text/html; charset=UTF-8
Fetch mode
static
Size
164805 bytes
SHA-256 (raw)
557cd76214c665280e76dac06a28ea8c9b09adc1fb23d203a833b5ef80e4f3eb
SHA-256 (normalized text)
69bd68057a8c0ac37992d9e032b8f24aa4e627f8c7e4f4175ad86257c3bec8c9

Normalized text

Scripts and page chrome removed; this is what change detection compares.

PRIVACY AND DATA PROTECTION POLICY
1. INTRODUCTION
Coaktion’s purpose is to simplify the complexity of digital transformation and elevate the customer experience. We know that trust is the foundation of any relationship, and therefore we are committed to ensuring the privacy and protection of personal data collected and processed within our companies’ ecosystem (Aktie Now, Callwe, Droz, Workise, and Syntrika).
This Policy meets the requirements of applicable data protection laws, including Brazil’s LGPD (Lei Geral de Proteção de Dados / General Data Protection Law), the European Union’s GDPR (General Data Protection Regulation), and United States privacy laws (such as the CCPA/CPRA – California Consumer Privacy Act / California Privacy Rights Act), and is aligned with international best practices in privacy management (ISO/IEC 27701) and information security (ISO/IEC 27001 and 27002).
Questions about applicable legislation and/or processes involving the collection or use of Personal Data should be directed to Coaktion’s DPO (Data Protection Officer) exclusively through the official channel:
Email: [email protected]
2. DEFINITIONS
For the purposes of this Privacy and Personal Data Protection Policy (“Policy”), the terms and expressions used shall have the meanings defined below:
Applicable Data Protection Laws: Refers to all legislation in force on privacy and personal data protection in the jurisdictions where Coaktion operates, including the LGPD (Brazil), the GDPR (European Union), and U.S. state privacy laws.
Information Security and Compliance Committee: a committee formed by Coaktion personnel, whose function is to support Coaktion’s directors and its DPO (Data Protection Officer) in decision-making regarding the group’s Information Security Management System and Privacy and Data Protection Management System.
Personnel: includes employees, partners, service providers, and any other person with a direct relationship with the company.
Data Subject: the natural person to whom the personal data subject to processing refers.
Personal Data: data related to a natural person that allows, directly or indirectly, their identification.
Sensitive Personal Data: personal data concerning racial or ethnic origin, religious belief, political opinion, union or religious/philosophical/political organization membership, data concerning health or sexual life, genetic or biometric data, as well as other data specifically considered sensitive under applicable laws and regulations.
Direct Data: data that directly identifies a specific data subject without the need for additional information to identify them.
Indirect Data: data that cannot be attributed to a data subject without the use of additional information to identify them.
Pseudonymized Data: data processed using techniques that mask its attribution to a data subject, but which can be reversed to its natural state.
Anonymized Data: data related to a data subject that does not allow their identification through the use of reasonable technical means available at the time of processing. Processing Agents: refer to the Controller and the Processor.
Data Controller: a natural or legal person, of public or private law, responsible for decisions regarding the processing of personal data.
Data Processor: a natural or legal person, of public or private law, who processes personal data on behalf of the Controller.
Data Protection Officer or DPO: a person appointed by the Controller and/or Processor to act as a communication channel with data subjects and competent Supervisory Authorities.
Data Processing: any operation carried out with personal data, such as collection, production, receipt, classification, use, access, reproduction, transmission, distribution, processing, filing, storage, elimination, evaluation or control of information, modification, communication, transfer, dissemination, or extraction of personal data.
Purpose: carrying out processing for legitimate, specific, explicit purposes communicated to the data subject, with no possibility of subsequent processing incompatible with these purposes.
Necessity: limiting processing to the minimum necessary to achieve its purposes, covering data that is relevant, proportional, and not excessive in relation to the purposes of the processing.
Consent: free, informed, and unambiguous expression by which the data subject agrees to the processing of their personal data for a determined and specific purpose.
Legal Basis: justifications used to legitimize the processing of personal data.
Cookies: considered identifiers, i.e., generated and collected from the browser, for the purpose of identifying a browsing profile or facilitating access to a web page.
Record of Personal Data Processing Operations (ROPA): documentation containing how personal data processing activity is carried out.
Data Protection Impact Assessment (DPIA): documentation describing personal data processing operations that may create risks to the civil liberties and fundamental rights of data subjects, as well as the measures, safeguards, and risk mitigation mechanisms adopted.
Supervisory or Control Authority: the public administration body or governmental entity responsible for overseeing compliance with data protection laws (such as the ANPD – Autoridade Nacional de Proteção de Dados / National Data Protection Authority in Brazil, or the Data Protection Authorities – DPAs in Europe).
Privacy by Design: a principle establishing that privacy and data protection must be integrated into the design and architecture phase of any new system, product, or process.
Privacy by Default: a principle ensuring that, by default, only the personal data strictly necessary for each specific purpose is processed.
3. OBJECTIVE
To define the guidelines and rules applicable to the Processing of Personal Data within the Coaktion ecosystem, ensuring an adequate level of protection, transparency, and compliance with Applicable Data Protection Laws and the regulations of Supervisory Authorities. This policy guides the behavior of all personnel and partners, ensuring that data subjects’ rights are respected and that privacy risks are mitigated pragmatically and continuously.
4. APPLICABILITY AND SCOPE
This Policy applies to all companies in the Coaktion ecosystem (Aktie Now, Callwe, Droz, and Workise), covering all personnel, service providers, suppliers, and business partners who use the processing environment and/or have access to Coaktion’s information or that of its Clients.
The scope of this policy covers all forms of processing, automated or manual, and recognizes that Coaktion acts under two distinct roles before the Applicable Data Protection Laws:
Coaktion acts as a Data Controller when it makes decisions about the processing of personal data. This occurs in internal and administrative processes, such as:
Recruitment, selection, and management of personnel and service providers;
Hiring of suppliers and business partners;
Coaktion’s own marketing, sales, and commercial relationship activities;
Compliance with legal, labor, and regulatory obligations.
Coaktion acts as a Data Processor when it processes personal data on behalf of and according to the instructions of its Clients (who are the Data Controllers). This is the main activity of our ecosystem in the services provided, such as:
Implementation and support of partner platforms (e.g., Zendesk, Salesforce, monday.com) carried out by Aktie Now and Workise;
Processing of voice and communication flows through the Callwe platform;
Interactions, automations, and support guided by Artificial Intelligence through the Droz platform.
In these cases, Coaktion will apply the guidelines of this policy together with the contractual guidelines established with each Controller Client, ensuring the technical and organizational security of operations.
This Policy has global scope. Should conflicts exist between the guidelines established herein and the local laws of a specific jurisdiction where Coaktion operates, the rule offering the greatest level of protection to the data subject shall prevail.
5. PRIVACY PRINCIPLES AND GUIDELINES
The Processing of Personal Data under the responsibility of the Coaktion ecosystem is carried out in strict observance of the Applicable Data Protection Laws, based on the following organizational principles and guidelines:
i) Purpose and Necessity:
The collection and processing of data must have legitimate, specific, and informed purposes. We process only the data strictly necessary (minimum privilege) to achieve business purposes or fulfill contracts.
ii) Privacy by Design and by Default:
The development of new products (such as Droz’s AI solutions) and the implementation of client projects (Aktie Now and Workise) must consider data protection from their initial architecture, ensuring that the highest level of privacy is the system’s default.
iii) Transparency and Free Access:
We guarantee data subjects clear and accessible information about the processing carried out and the respective agents involved.
iv) Security and Prevention:
We implement rigorous technical and organizational controls (described in our General Information Security Policy – PGSI) to protect data against unauthorized access, destruction, loss, alteration, or leakage.
v) Legal Bases:
No personal data is processed without a valid legal basis, as defined by the legislation of each jurisdiction (e.g., Art. 7 and 11 of the LGPD, Art. 6 of the GDPR, or applicable sections of the CCPA/CPRA).
6. SUBCONTRACTING OF PROCESSORS (SUB-PROCESSORS)
As a technology ecosystem, Coaktion uses cloud infrastructure and third-party platforms to support its operations and the provision of services to its clients. Therefore:
Use of Sub-processors:
Coaktion subcontracts technology services (such as cloud computing providers and SaaS platforms) that act as sub-processors in data processing.
Due Diligence and Compliance:
The choice of any sub-processor is conditional on prior assessments (due diligence). We contractually require our sub-processors to adopt technical and organizational information security measures compatible with this Policy, with the Applicable Data Protection Laws, and with ISO 27001 and 27701 standards.
Transparency with the Controller:
When Coaktion acts as a Processor, the list of global sub-processors used in the provision of the service is made available to our Clients (Controllers) and is governed by the respective service agreements and contracts.
7. INTERNATIONAL TRANSFERS
Due to the global nature of cloud services and partner platforms used in our ecosystem (e.g., hosting providers, CRM systems, and process management), Coaktion carries out international transfers of personal data.
To ensure the legality and security of these operations, Coaktion undertakes to carry out international transfers exclusively under the following circumstances (in accordance with the guidelines of competent Supervisory Authorities, such as the ANPD in Brazil or the European Commission):
i) To countries or international organizations that provide an adequate level of personal data protection, recognized by the competent authorities;
ii) Through the use of valid contractual guarantees, such as the adoption of Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs), or regularly issued compliance seals and certificates.
iii) Coaktion ensures that international partners provide technical security safeguards equivalent to those required by the Applicable Data Protection Laws.
8. RIGHTS OF PERSONAL DATA SUBJECTS
Coaktion ensures Data Subjects the full exercise of their rights, as provided for in the Applicable Data Protection Laws (such as Art. 18 of the LGPD, Chapter III of the GDPR, and U.S. regulations). Every request received will be reviewed by the DPO (Data Protection Officer) and answered within the applicable legal deadlines. Guaranteed rights include:
i) Confirmation of the existence of processing and facilitated access to data;
ii) Correction of incomplete, inaccurate, or outdated data;
iii) Anonymization, blocking, or deletion of unnecessary or excessive data, or data processed in violation of the law;
iv) Portability of data to another service or product provider, upon express request;
v) Deletion of personal data processed with the data subject’s consent (except in cases of legal custody);
vi) Clear information about the public and private entities with which the controller has shared data;
vii) Information about the possibility of not giving consent and the consequences of refusal, as well as the right of revocation;
viii) Right to opt out of the sale or sharing of personal data, as applicable under U.S. state privacy laws.
9. COOKIES AND TRACKERS
On its portals, platforms, and web applications, Coaktion may use cookies and identifiers (first-party or third-party) to optimize the user experience, ensure page performance, and for analytical and marketing purposes.
Detailed guidelines, as well as the categories of cookies used and how the data subject can manage them, must be publicly described in the specific Privacy and Cookies Notice of each Coaktion website.
Coaktion ensures the implementation of consent management tools (cookie banners) on its portals, allowing users clear choices about their use.
10. DATA RETENTION
In line with the principles of necessity and adequacy, Coaktion will retain Personal Data and Sensitive Personal Data only for the period strictly necessary to achieve the specific purposes for which it was collected.
The retention period will respect the legal, regulatory, tax, and contractual obligations in force for our business, or the period strictly necessary for the regular exercise of rights.
The definition of specific retention periods for each process will be mapped, evaluated, and documented in our Record of Personal Data Processing Operations (ROPA), ensuring that, after the purpose or legal deadline has ended, data is securely deleted or anonymized.
11. RECORD OF PERSONAL DATA PROCESSING OPERATIONS (ROPA)
Coaktion, in compliance with the Applicable Data Protection Laws (such as the LGPD in Brazil) and good governance practices, maintains a duly documented and updated record of its personal data processing operations (ROPA).
To ensure greater organization and security in audits, each business unit of the ecosystem (Coaktion, Aktie Now, Callwe, Droz and Workise, Syntrika) will have its own ROPA, reflecting the specifics of its services and its role as Data Controller or Processor.
The management, technical support, and periodic validation of these records will be centralized with the DPO (Data Protection Officer) and/or Coaktion’s corporate Privacy area.
12. DATA PROTECTION IMPACT ASSESSMENT (DPIA)
Coaktion conducts privacy risk assessments to identify possible impacts on the rights and civil liberties of data subjects.
Preparation of a DPIA is mandatory across all group companies before implementing new processes, projects, systems, or policies involving high-risk data processing, emerging technologies (such as Artificial Intelligence), or Sensitive Personal Data.
The document must describe the necessity and purpose of the processing, the data flows, the risks identified, the proposed solutions, and the safeguards adopted.
Residual risks identified that are not immediately mitigated must be formally recorded and submitted for risk acceptance by Senior Management.
13. ACTIONS FOR POLICY IMPLEMENTATION
Awareness and Culture Building:
Coaktion will ensure the continuous implementation of a privacy and data protection education program for all its personnel and service providers. The relevance of the topic will be reiterated in day-to-day operations, from onboarding to annual training, the guidelines and effectiveness metrics of which are detailed in our Information Security Culture and Awareness Policy.
The Data Protection Officer (DPO):
Coaktion will appoint a DPO (Data Protection Officer), who will be responsible for coordinating operational actions to implement the privacy strategy, monitoring compliance with the Applicable Data Protection Laws, and mediating official communication between Data Subjects, the organization, and competent Supervisory Authorities.
The DPO’s contact information will be centralized and easily accessible through Coaktion’s official channels and Privacy Notices.
Privacy and Personal Data Protection Committee:
To support the DPO in management, strategic decision-making, and control of the Privacy Program, Coaktion establishes a multidisciplinary Committee. The Committee will be composed of strategic representatives from the business, technology, and operations units, ensuring that privacy decisions are applicable and do not create unnecessary friction with the services provided by the ecosystem.
Technical Measures and Audits:
Coaktion will adopt robust technical and organizational policies and resources to prevent, detect, and monitor potential violations of the LGPD. The implementation of this Policy and its resulting actions will be subject to continuous monitoring and periodic internal audits, ensuring compliance with ISO 27701.
14. SERVICE CHANNEL AND COMPLAINT REGISTRATION
Coaktion centralizes all requests, petitions, and complaints regarding Personal Data Processing with the DPO (Data Protection Officer).
Data Subjects wishing to exercise their rights (as described in item 8 of this Policy) or report incidents must send their request exclusively to the official email: [email protected].
Requests will be received, reviewed, and answered clearly and completely within 15 (fifteen) days, or as required by the Applicable Data Protection Laws of each jurisdiction.
15. INVESTIGATION AND COMMUNICATION OF SECURITY INCIDENTS
Coaktion has rigorous information security processes. However, in the event of any suspected or confirmed security incident involving personal data (such as leakage, destruction, loss, alteration, or unauthorized access), the following guidelines must be strictly observed:
Internal Notification: Every employee, service provider, or partner must immediately notify the DPO ([email protected]) and the Corporate Technology area upon becoming aware of an adverse event.
Coaktion as Processor: If the incident affects data processed on behalf of our Clients (Controllers), Coaktion will formally notify them without undue delay, providing all necessary technical support for the investigation and mitigation of risks.
Coaktion as Controller: If the incident affects data under Coaktion’s control and may cause significant risk or harm to data subjects, Coaktion will make official communication to the Supervisory Authorities and affected data subjects within the period stipulated by the legislation in force in each jurisdiction (e.g., 72 hours under the GDPR or 3 business days under the ANPD).
16. MUTUAL ASSISTANCE AND COOPERATION WITH SUPERVISORY AUTHORITIES
Coaktion will act collaboratively with Supervisory Authorities and other competent authorities on data privacy matters. We are committed to responding to information requests, adopting good practices, and facilitating inspections, always within legal limits and safeguarding our trade and industrial secrets. The DPO is the exclusive point of contact to mediate this communication.
17. REVISIONS AND UPDATES
This Privacy and Data Protection Policy takes effect from the date of its approval and publication, remaining in force for an indefinite period and revoking any provisions to the contrary. To ensure its continuous adequacy in light of technological changes, operational needs, or new resolutions from Supervisory Authorities, this document will be critically reviewed and updated at least annually, or whenever necessary, by the Privacy area with the support of the DPO and Senior Management.
ANNEX I
Qualification of Coaktion Group Companies:
AKTIE PARTICIPAÇÕES LTDA. (Coaktion), a limited liability company headquartered at Rua Manoel Coelho, No. 676, Suite 710, Centro, city of São Caetano do Sul, State of São Paulo, ZIP Code 09510-101, enrolled with the CNPJ/ME (National Corporate Taxpayer Registry) under No. 33.108.579/0001-60, with its incorporation documents duly filed with JUCESP (São Paulo Board of Trade) under NIRE 35231427106 (“Coaktion”).
AKTIE NOW SERVIÇOS TECNOLÓGICOS E EMPRESARIAIS LTDA., a limited liability company headquartered at Rua Manoel Coelho, No. 676, Suite 710, Centro, city of São Caetano do Sul, State of São Paulo, ZIP Code 09510-101, enrolled with the National Corporate Taxpayer Registry of the Ministry of Economy (“CNPJ/ME”) under No. 24.552.976/0001-35, with its incorporation documents duly filed with the São Paulo Board of Trade (“JUCESP”) under Company Registration Identification Number (“NIRE”) 3522978790 (“AKTIE NOW”).
DROZ TECNOLOGIA DA INFORMAÇÃO LTDA., a limited liability company headquartered at Rua Manoel Coelho, No. 676, Suite 710, Centro, city of São Caetano do Sul, State of São Paulo, ZIP Code 09510-101, enrolled with the CNPJ/ME under No. 30.488.257/0001-03, with its incorporation documents duly filed with JUCESP under NIRE 35230962628 (“DROZ”).
MYPBX SERVIÇOS E TECNOLOGIA LTDA., a limited liability company headquartered at Rua Manoel Coelho, No. 676, Suite 710, Centro, city of São Caetano do Sul, State of São Paulo, ZIP Code 09510-101, enrolled with the CNPJ/ME under No. 10.717.581/0001-30, with its incorporation documents duly filed with JUCESP under NIRE 35223070113 (“MYPBX”).
SYNTRIKA SERVICOS TECNOLOGICOS E EMPRESARIAIS LTDA., a limited liability company headquartered at Rua Manoel Coelho, No. 676, Suite 710, Centro, city of São Caetano do Sul, State of São Paulo, ZIP Code 09510-101, enrolled with the CNPJ/ME under No. 62.029.390/0001-80, with its incorporation documents duly filed with JUCESP under NIRE No. 35267576713 (“Syntrika”).
CO.AKTION LLC, a limited liability company headquartered at 2 S. Biscayne Boulevard, Suite 2450, Miami, FL 33131, United States of America, enrolled with the Employer Identification Number (EIN) under No. 87-1734016.