Privacy Policy | Shooting House

PRIVACY AND DATA PROTECTION POLICY

 

Version ID: POLTI-002

Established – Updated: 01/09/2024

  1. Purpose

The Information Security and Privacy Policy is a formal statement by SHOOTING HOUSE establishing its commitment to information security and to the protection and proper processing of personal data used in its operational and management processes throughout the entire life cycle.

This document guides and establishes the guidelines to be observed by everyone directly or indirectly involved in the organization’s activities, aiming to guarantee the confidentiality, integrity, availability and authenticity of information, as well as respect for the rights of personal data subjects regarding the processing of their data. Accordingly, the guidelines presented here set out the appropriate conduct to be adopted for the handling, processing, control and protection of personal data, information, documents and knowledge collected, produced, stored and transmitted in the organization’s activities against threats and vulnerabilities related to information security and privacy.


  1. Scope and Coverage


The Information Security and Privacy Policy consists of rules, guidelines, procedures and responsibilities, and must be followed by all officers, employees and third parties who are in any way carrying out activities that may pose a risk to the confidentiality, integrity, availability and authenticity of the organization’s information, as well as to the protection of personal data, whether these activities take place inside or outside the organization’s physical premises.


  1. Terms and definitions

 

  • 3.1. Asset: anything that handles data or information, including the information itself, such as plans, processes, procedures, databases, files, system documentation, manuals, training materials, stored information, software, systems, tools, utilities, workstations, servers, communication equipment, UPS units and others;

  • 3.2. Processing agents: the controller and the processor;

  • 3.3. Information asset: an asset that stores data or information;

  • 3.4. Information Security Committee (CSI): a group of people responsible for advising on the implementation of information security and communications actions within the organization;

  • 3.5. Controller: a natural or legal person, governed by public or private law, responsible for decisions regarding the processing of personal data;

  • 3.6. Personal data: information relating to an identified or identifiable natural person;

  • 3.7. Sensitive personal data: personal data on racial or ethnic origin, religious belief, political opinion, membership of a trade union or of a religious, philosophical or political organization, data concerning health or sex life, genetic or biometric data, when linked to a natural person;

  • 3.8. Anonymized data: data relating to a data subject who cannot be identified, considering the use of reasonable technical means available at the time of processing;

  • 3.9. Pseudonymized data: a mechanism for disguising identity by replacing one attribute with another.

  • 3.10. Data Protection Officer: a person appointed by the controller and processor to act as a communication channel between the controller, the data subjects and the Brazilian National Data Protection Authority (ANPD);

  • 3.11. Information Security Incident: any adverse event, confirmed or suspected, related to the security of information systems, leading to the loss of one or more basic principles of Information Security: authenticity, confidentiality, integrity and availability;

  • 3.12. Privacy Incident: any adverse event, confirmed or suspected, related to the protection of personal data, leading to the loss of one or more basic principles of Personal Data Protection: purpose, adequacy, necessity, free access, data quality, transparency, security, prevention, non-discrimination, and accountability;

  • 3.13. Information: the result of processing, handling and organizing data in such a way that it represents a change (quantitative or qualitative) in the knowledge of the system (human or computational) that receives it;

  • 3.14. Protective measures: measures intended to guarantee secrecy, when necessary, inviolability, integrity, authenticity, legitimacy and availability of data and information, with the aim of preventing, detecting, neutralizing or recording actual or potential threats to data and information;

  • 3.15. Non-repudiation: assurance that the sender of a message will not later deny authorship of the message or transaction, allowing their identification;

  • 3.16. Processor: a natural or legal person, governed by public or private law, that processes personal data on behalf of the controller;

  • 3.17. Business Continuity Plan: describes the actions to be taken to ensure the continuity of critical processes in the event of disasters at the organization or system failures, including the activation of manual processes, resource redundancy, staff relocation and engagement of service providers;

  • 3.18. Information Security Policy: recommendations intended to establish criteria for the proper handling, storage, transport and disposal of information through the development of guidelines, rules, procedures and instructions aimed, respectively, at the strategic, tactical and operational levels;

  • 3.19. Service Providers: a legal or natural person that holds a service agreement with the organization;

  • 3.20. Information Owner: the person responsible for classifying and authorizing access to information;

  • 3.21. Information Security: a set of controls aimed at preserving the confidentiality, integrity and availability of information;

  • 3.22. Secrecy: a property of information indicating that access to it by unauthorized persons is prevented;

  • 3.23. Statement of Responsibility: a document that formalizes the obligation of employees and third parties regarding the safekeeping and processing of information, according to its established confidentiality level, and the proper use of the computing resources provided by the organization;

  • 3.24. Data Subject: the natural person to whom the personal data being processed refers;

  • 3.25. User: a person who uses information technology (IT) resources and services on a daily basis, who may be an employee, fixed-term contractor, outsourced service provider, intern, among others.

 

  1. Principles

 

The organization operates in accordance with the guidelines established in this Information Security and Privacy Policy, observing the principles of legality, impersonality, morality, publicity, efficiency, purpose, public interest, transparency and justification of administrative acts. Accordingly, the improper, negligent or reckless use of the resources and services granted to its employees and third parties will be subject to analysis of data and evidence in order to obtain proof to be used in investigative proceedings, as well as for the adoption of applicable legal measures.

  • 4.1. Information Security Principles:

In order to ensure information security, the organization seeks to comply with the following principles:

Confidentiality: assurance that access to the information asset is restricted to authorized persons only;

Integrity: assurance that information is kept in its original state, protecting it, in storage or transmission, against improper, intentional or accidental changes;

Availability: assurance that users can access information and the corresponding assets when needed;

  • 4.2. Privacy Principles:

In order to ensure the privacy of personal data subjects, the organization seeks to comply with the following principles pursuant to Article 6 of the LGPD (Brazilian General Data Protection Law):

Purpose: processing carried out for legitimate, specific, explicit purposes communicated to the data subject, with no possibility of subsequent processing in a manner incompatible with those purposes;

Adequacy: compatibility of the processing with the purposes communicated to the data subject, according to the context of the processing;

Necessity: limitation of processing to the minimum necessary to achieve its purposes, covering data that is relevant, proportionate and not excessive in relation to the purposes of the data processing;

Free access: assurance to data subjects of easy, free-of-charge consultation on the form and duration of processing, as well as on the entirety of their personal data;

Data quality: assurance to data subjects of the accuracy, clarity, relevance and currency of data, as necessary and for the fulfillment of the purpose of its processing;

Transparency: assurance to data subjects of clear, accurate and easily accessible information on the processing carried out and the respective processing agents, subject to trade and industrial secrets;

Security: use of technical and administrative measures capable of protecting personal data from unauthorized access and from accidental or unlawful destruction, loss, alteration, communication or dissemination;

Prevention: adoption of measures to prevent the occurrence of harm as a result of personal data processing;

Non-discrimination: processing may not be carried out for unlawful or abusive discriminatory purposes;

Accountability: demonstration, by the agent, of the adoption of effective measures capable of proving observance of and compliance with personal data protection rules, including the effectiveness of those measures.


  1. Legal bases for the processing of personal data:


For legal compliance, the organization processes personal data only in the following cases, pursuant to Article 7 of the LGPD:

  • Upon consent given by the data subject;
  • Compliance with a legal or regulatory obligation by the controller;
  • By the public administration, for the processing and shared use of data necessary for the execution of public policies provided for in laws and regulations or supported by contracts, agreements or similar instruments;
  • For studies carried out by research bodies, ensuring, whenever possible, the anonymization of personal data;
  • When necessary for the performance of a contract or preliminary procedures related to a contract to which the data subject is a party, at the request of the data subject;
  • For the regular exercise of rights in judicial, administrative or arbitration proceedings;
  • For the protection of the life or physical safety of the data subject or third parties;
  • For the protection of health, exclusively in procedures carried out by health professionals, health services or health authorities;
  • To meet the legitimate interests of the controller or third parties, except where the fundamental rights and freedoms of the data subject that require the protection of personal data prevail;
  • For credit protection.

 

  1. Personal data we may collect and store through collection from software subscribers and their use of it.

Information relating to natural persons should only be collected to the extent necessary for the provision of services, and in all applicable cases the processing of data must be carried out in compliance with the Brazilian General Data Protection Law.

Within the limits established by applicable legislation, the categories and types of personal data collected by Shooting House may include, subject to the guiding principles listed in the previous item: 

  • Your contact information, such as name, company name, email address, telephone or postal address, including but not limited to that used to communicate with you;
  • For competitions: Full name, Shooter identification number, Membership of a shooting association or club;
  • For gun stores: Customer’s full name; Email address; Telephone number; Address information and Purchase History;
  • For dispatchers: Applicant’s full name, date of birth, personal identification number, home address, contact information, applicant’s marital status, criminal record, proof of residence, mental health history.
  • For clubs and finance: Identification information, including but not limited to that used to communicate with you, membership history, training information, information on firearms owned, record of participation in events or competitions;
  • Account information, such as username, user ID, and data about your registration in the SH software;  
  • Professional or employment-related information, such as professional details, résumé, cover letter;

Personal data may also be obtained directly by Shooting House through interactions and through its products and services, and personal data collected online may also be combined with personal data provided through offline channels, such as during a meeting, job interviews, events held, and also automatically, in connection with the use of our websites and responses to our emails through the use of various technologies.

The data may be used to identify and authenticate the user when accessing Shooting House services, and in the processing of personal information in order to fulfill contractual obligations entered into with employees, third parties, partners and customers, always aiming to ensure the security of personal data.

 

  1. Shared responsibility.

Responsibility for the proper processing of personal data within the company is shared among all those who act as processors, and the cooperation of everyone is essential for the company to always remain compliant with the law, providing security for all personal data under its control.

Shooting House may disclose personal data to business partners and service providers to support our operations. Such business partners and service providers are contractually required to keep the information received on behalf of Shooting House confidential and secure, and not to use it for any purpose other than that for which it was provided to them.

The sharing of personal data with persons or entities outside Shooting House must be restricted to the minimum necessary for the performance of the contracts and services in which the data subjects are involved, or for compliance with any legal obligation. Even when the processing directly involves the provision of services, the appropriate legal basis will be assigned for such processing and sharing.

Shooting House may also disclose personal data as required by law or legal process, when essential for compliance with legal, judicial and administrative orders and/or for the exercise of the right of defense in judicial and administrative proceedings, and such data will be retained notwithstanding the deletion of other data. 

Pursuant to Article 42 et seq. of the Brazilian General Data Protection Law (Law 13,709 of August 14, 2018), a personal data processor that fails to comply with the controller’s lawful data protection guidelines – in this case, Shooting House – shall be jointly and severally liable, and is therefore subject to civil, administrative and criminal liability for the improper processing of data.

External sharing of personal data of customers or company members – by any means, telephone, digital or written – without their authorization is prohibited, and the data subject shall be duly informed whenever data is shared in a new context.


  1. Processing of personal data at Shooting House.

The processing of personal data at Shooting House must follow the principles defined in this policy and must be strictly limited to the purposes for which the data was collected, respecting the principles of this policy, the information sharing and security criteria, and the applicable legislation.

Personal data must be processed only by people who need to handle it. This reduces the risk of human error leading to a leak or improper use of information. The best way to ensure this is to divide data by department and by specific responsibilities within each department. This way, in every situation it will be known who the data processors are, and the risk of an information security incident is considerably reduced.

To ensure this departmentalized processing of data, each Shooting House employee’s or service provider’s access to the company’s database is individual and protected by a personal, non-transferable password. Thus, only people authorized to handle identifiable personal data of employees and contractors, for example, will be able to access it.

The mere access to and/or improper use of any personal data stored in technological waste processed by the company is strictly prohibited, under penalty of dismissal for cause (or termination of the service agreement), without prejudice to applicable civil and criminal liability in court.


  1. Period for which data will be stored.


Personal data collected by Shooting House will be used and stored for the time necessary to provide the service or to achieve the purposes listed in this Privacy Policy, considering the rights of data subjects and controllers. Thus, data will be retained for as long as the contractual relationship between the data subject and Shooting House lasts and, once the personal data storage period has ended, it will be deleted from our databases or anonymized, except in the cases legally provided for in Article 16 of the LGPD, namely:

I – compliance with a legal or regulatory obligation by the controller;

II – studies by research bodies, ensuring, whenever possible, the anonymization of personal data;

III – transfer to a third party, provided that the data processing requirements set out in this Law are respected; or

IV – exclusive use by the controller, with access by third parties prohibited, and provided that the data is anonymized.

Thus, once the purpose of processing personal data has been achieved and it no longer needs to be stored to satisfy any legal requirements, it must, except in the cases in the previous paragraph, be duly deleted physically and digitally, with notice of this deletion given to the data subject in cases where it takes place in a manner different from that provided for in the applicable consent form.

Therefore, Shooting House commits to the security and privacy of the personal data collected, through the use of technical protection measures and solutions capable of guaranteeing the confidentiality, integrity and inviolability of the data, along with security measures appropriate to the risks and access control for stored information.


  1. Security measures and data storage criteria.


To keep your personal information secure, we use physical, electronic and managerial tools aimed at protecting your privacy. We apply these tools taking into account the nature of the personal data collected, the context and purpose of the processing, and the risks that any breaches would pose to the rights and freedoms of the subject of the data collected and processed.

Shooting House commits to adopting best practices to prevent security incidents, based on the good practices set out in ISO 27001/27002 and Law 13,709/2018.

Any copies of personal data should only be made when necessary to fulfill the intended purpose of the processing, and all copies made must be logged, and such log must be kept digitally under the same security criteria.


  1. Provision of information, transparency and the data protection officer – DPO.


Shooting House commits to providing all information requested by data subjects regarding the processing of their personal data, respecting the company’s right to maintain trade secrets where applicable. The purpose of the processing must always be evident and transparent.

When a data subject requests information about their personal data, the processors must inform the Data Protection Officer of the request and then provide the requested information to the data subject.

The data protection officer will be the person responsible – under the LGPD – for communication between data subjects, Shooting House and the Brazilian National Data Protection Authority (ANPD). The officer’s duties include assessing existing risks, identifying corrective measures and periodically evaluating the security of personal data within the company, as well as carrying out any necessary communications with data subjects or public authorities. Any questions that arise in the company’s day-to-day operations regarding the protection of personal data must be brought to the Officer so that they can immediately guide the processor or seek appropriate guidance from the ANPD and other specialized bodies on the question raised.

The Data Protection Officer will maintain a risk and impact assessment report on personal data protection, through which the measures necessary for the information security of personal data can be structured, implemented and evaluated.

Shooting House has appointed LGPD CONSULTORIA DIGITAL as its Data Protection Officer, making the following contact channel available for you to exercise your rights as a data subject: email [email protected].

Hello,

How can we help you?