Privacy and Personal Data Protection Policy

No: LGPD-03  |  Revision: 03  |  Date: June 04, 2025  |  Type: Policy  |  São Paulo

The need to ensure that administrative activities within ILLIX, hereinafter referred to as the “Controller”, are conducted in compliance with Law No. 13,709/2018, also known as the General Data Protection Law (LGPD), enacted with the objective of protecting the fundamental rights of freedom and privacy, as well as establishing rules on the collection, use, storage, and sharing of data.

For questions, we recommend reading: General Data Protection Law

Principles

Always in the performance of legitimate and specific purposes, we process Personal Data based on the following principles:

General Principles of LGPD

Rights of Data Subjects

Processing of Personal Data

We exercise typical activities of a Controlling Treatment Agent and Operator. When the action of an Operating Agent is necessary, we establish a written contract defining the object, purpose, and obligations in accordance with the LGPD.

Sharing of Personal Data

ILLIX does not sell Personal Data and only shares it for legitimate and specific purposes.

With whom we share:

Data Retention

Data from customers, employees, and third parties will be retained for up to 5 years after departure or termination. After this period, data will be deleted or, in the case of physical documents, shredded.

How to Talk About Your Data

If you believe your personal data has been processed in a manner incompatible with this Policy, contact us through the privacy portal: https://www.helloethics.com/illix/lgpd or via email at dpo@illix.com.br.

Glossary

Database

For questions or information about your report data not found on this page, contact our DPO (Data Protection Officer) at dpo@illix.com.br.

Cookies

Small files temporarily stored on the USER'S computer, used to identify browsing preferences and other information related to their visit to a particular website/web page.

Personal Data

Information that identifies or makes the REPORTER identifiable.

Sensitive Personal Data

Data about racial or ethnic origin, religious conviction, political opinion, union membership, or organization of a religious, philosophical, or political nature, data concerning health or sex life, genetic or biometric data when linked to a natural person.

Data Processing

Any operation performed with personal data, such as those referring to: collection, production, reception, classification, use, access, reproduction, transmission, distribution, processing, filing, storage, elimination, evaluation or control of information, modification, communication, transfer, dissemination, or extraction.

Reporter

Any natural person who accesses and/or uses the functionalities of Hello Ethics.

Personal Data Breach

A security incident that causes, accidentally or unlawfully, the destruction, loss, alteration, disclosure, or unauthorized access to personal data.

Consent

Free, informed, and unambiguous manifestation by which the subject agrees to the processing of their personal data for a determined purpose.

Anonymization

Use of reasonable and available technical means at the time of processing, through which a piece of data loses the possibility of direct or indirect association with an individual.

Elimination

Deletion of data or a set of data stored in a database.