PRIVACY AND DATA PROTECTION POLICY
Version ID: POLTI-002
Established – Updated: 01/09/2024
The Information Security and Privacy Policy is a formal statement by SHOOTING HOUSE establishing its commitment to information security and to the protection and proper processing of personal data used in its operational and management processes throughout the entire life cycle.
This document guides and establishes the guidelines to be observed by everyone directly or indirectly involved in the organization’s activities, aiming to guarantee the confidentiality, integrity, availability and authenticity of information, as well as respect for the rights of personal data subjects regarding the processing of their data. Accordingly, the guidelines presented here set out the appropriate conduct to be adopted for the handling, processing, control and protection of personal data, information, documents and knowledge collected, produced, stored and transmitted in the organization’s activities against threats and vulnerabilities related to information security and privacy.
The Information Security and Privacy Policy consists of rules, guidelines, procedures and responsibilities, and must be followed by all officers, employees and third parties who are in any way carrying out activities that may pose a risk to the confidentiality, integrity, availability and authenticity of the organization’s information, as well as to the protection of personal data, whether these activities take place inside or outside the organization’s physical premises.
The organization operates in accordance with the guidelines established in this Information Security and Privacy Policy, observing the principles of legality, impersonality, morality, publicity, efficiency, purpose, public interest, transparency and justification of administrative acts. Accordingly, the improper, negligent or reckless use of the resources and services granted to its employees and third parties will be subject to analysis of data and evidence in order to obtain proof to be used in investigative proceedings, as well as for the adoption of applicable legal measures.
In order to ensure information security, the organization seeks to comply with the following principles:
Confidentiality: assurance that access to the information asset is restricted to authorized persons only;
Integrity: assurance that information is kept in its original state, protecting it, in storage or transmission, against improper, intentional or accidental changes;
Availability: assurance that users can access information and the corresponding assets when needed;
In order to ensure the privacy of personal data subjects, the organization seeks to comply with the following principles pursuant to Article 6 of the LGPD (Brazilian General Data Protection Law):
Purpose: processing carried out for legitimate, specific, explicit purposes communicated to the data subject, with no possibility of subsequent processing in a manner incompatible with those purposes;
Adequacy: compatibility of the processing with the purposes communicated to the data subject, according to the context of the processing;
Necessity: limitation of processing to the minimum necessary to achieve its purposes, covering data that is relevant, proportionate and not excessive in relation to the purposes of the data processing;
Free access: assurance to data subjects of easy, free-of-charge consultation on the form and duration of processing, as well as on the entirety of their personal data;
Data quality: assurance to data subjects of the accuracy, clarity, relevance and currency of data, as necessary and for the fulfillment of the purpose of its processing;
Transparency: assurance to data subjects of clear, accurate and easily accessible information on the processing carried out and the respective processing agents, subject to trade and industrial secrets;
Security: use of technical and administrative measures capable of protecting personal data from unauthorized access and from accidental or unlawful destruction, loss, alteration, communication or dissemination;
Prevention: adoption of measures to prevent the occurrence of harm as a result of personal data processing;
Non-discrimination: processing may not be carried out for unlawful or abusive discriminatory purposes;
Accountability: demonstration, by the agent, of the adoption of effective measures capable of proving observance of and compliance with personal data protection rules, including the effectiveness of those measures.
For legal compliance, the organization processes personal data only in the following cases, pursuant to Article 7 of the LGPD:
Information relating to natural persons should only be collected to the extent necessary for the provision of services, and in all applicable cases the processing of data must be carried out in compliance with the Brazilian General Data Protection Law.
Within the limits established by applicable legislation, the categories and types of personal data collected by Shooting House may include, subject to the guiding principles listed in the previous item:
Personal data may also be obtained directly by Shooting House through interactions and through its products and services, and personal data collected online may also be combined with personal data provided through offline channels, such as during a meeting, job interviews, events held, and also automatically, in connection with the use of our websites and responses to our emails through the use of various technologies.
The data may be used to identify and authenticate the user when accessing Shooting House services, and in the processing of personal information in order to fulfill contractual obligations entered into with employees, third parties, partners and customers, always aiming to ensure the security of personal data.
Responsibility for the proper processing of personal data within the company is shared among all those who act as processors, and the cooperation of everyone is essential for the company to always remain compliant with the law, providing security for all personal data under its control.
Shooting House may disclose personal data to business partners and service providers to support our operations. Such business partners and service providers are contractually required to keep the information received on behalf of Shooting House confidential and secure, and not to use it for any purpose other than that for which it was provided to them.
The sharing of personal data with persons or entities outside Shooting House must be restricted to the minimum necessary for the performance of the contracts and services in which the data subjects are involved, or for compliance with any legal obligation. Even when the processing directly involves the provision of services, the appropriate legal basis will be assigned for such processing and sharing.
Shooting House may also disclose personal data as required by law or legal process, when essential for compliance with legal, judicial and administrative orders and/or for the exercise of the right of defense in judicial and administrative proceedings, and such data will be retained notwithstanding the deletion of other data.
Pursuant to Article 42 et seq. of the Brazilian General Data Protection Law (Law 13,709 of August 14, 2018), a personal data processor that fails to comply with the controller’s lawful data protection guidelines – in this case, Shooting House – shall be jointly and severally liable, and is therefore subject to civil, administrative and criminal liability for the improper processing of data.
External sharing of personal data of customers or company members – by any means, telephone, digital or written – without their authorization is prohibited, and the data subject shall be duly informed whenever data is shared in a new context.
The processing of personal data at Shooting House must follow the principles defined in this policy and must be strictly limited to the purposes for which the data was collected, respecting the principles of this policy, the information sharing and security criteria, and the applicable legislation.
Personal data must be processed only by people who need to handle it. This reduces the risk of human error leading to a leak or improper use of information. The best way to ensure this is to divide data by department and by specific responsibilities within each department. This way, in every situation it will be known who the data processors are, and the risk of an information security incident is considerably reduced.
To ensure this departmentalized processing of data, each Shooting House employee’s or service provider’s access to the company’s database is individual and protected by a personal, non-transferable password. Thus, only people authorized to handle identifiable personal data of employees and contractors, for example, will be able to access it.
The mere access to and/or improper use of any personal data stored in technological waste processed by the company is strictly prohibited, under penalty of dismissal for cause (or termination of the service agreement), without prejudice to applicable civil and criminal liability in court.
Personal data collected by Shooting House will be used and stored for the time necessary to provide the service or to achieve the purposes listed in this Privacy Policy, considering the rights of data subjects and controllers. Thus, data will be retained for as long as the contractual relationship between the data subject and Shooting House lasts and, once the personal data storage period has ended, it will be deleted from our databases or anonymized, except in the cases legally provided for in Article 16 of the LGPD, namely:
I – compliance with a legal or regulatory obligation by the controller;
II – studies by research bodies, ensuring, whenever possible, the anonymization of personal data;
III – transfer to a third party, provided that the data processing requirements set out in this Law are respected; or
IV – exclusive use by the controller, with access by third parties prohibited, and provided that the data is anonymized.
Thus, once the purpose of processing personal data has been achieved and it no longer needs to be stored to satisfy any legal requirements, it must, except in the cases in the previous paragraph, be duly deleted physically and digitally, with notice of this deletion given to the data subject in cases where it takes place in a manner different from that provided for in the applicable consent form.
Therefore, Shooting House commits to the security and privacy of the personal data collected, through the use of technical protection measures and solutions capable of guaranteeing the confidentiality, integrity and inviolability of the data, along with security measures appropriate to the risks and access control for stored information.
To keep your personal information secure, we use physical, electronic and managerial tools aimed at protecting your privacy. We apply these tools taking into account the nature of the personal data collected, the context and purpose of the processing, and the risks that any breaches would pose to the rights and freedoms of the subject of the data collected and processed.
Shooting House commits to adopting best practices to prevent security incidents, based on the good practices set out in ISO 27001/27002 and Law 13,709/2018.
Any copies of personal data should only be made when necessary to fulfill the intended purpose of the processing, and all copies made must be logged, and such log must be kept digitally under the same security criteria.
Shooting House commits to providing all information requested by data subjects regarding the processing of their personal data, respecting the company’s right to maintain trade secrets where applicable. The purpose of the processing must always be evident and transparent.
When a data subject requests information about their personal data, the processors must inform the Data Protection Officer of the request and then provide the requested information to the data subject.
The data protection officer will be the person responsible – under the LGPD – for communication between data subjects, Shooting House and the Brazilian National Data Protection Authority (ANPD). The officer’s duties include assessing existing risks, identifying corrective measures and periodically evaluating the security of personal data within the company, as well as carrying out any necessary communications with data subjects or public authorities. Any questions that arise in the company’s day-to-day operations regarding the protection of personal data must be brought to the Officer so that they can immediately guide the processor or seek appropriate guidance from the ANPD and other specialized bodies on the question raised.
The Data Protection Officer will maintain a risk and impact assessment report on personal data protection, through which the measures necessary for the information security of personal data can be structured, implemented and evaluated.
Shooting House has appointed LGPD CONSULTORIA DIGITAL as its Data Protection Officer, making the following contact channel available for you to exercise your rights as a data subject: email [email protected].