• Glossary:
LGPD: General Data Protection Law (LGPD) - Law No. 13,709/2018;
Term of Consent: Consent is defined as a clear and unambiguous statement from a person (Holder) who agrees to the use of their data for the purposes proposed by the company. For example: the Holder has provided his data to the company in a form and has marked that he is interested in receiving promotional emails from the company. He has consented to provide the information and also to be communicated about sales materials;
Legal basis: these are criteria established by the LGPD, to describe in which situations the processing of data is allowed without the need for user consent;
DPO: from the English "Data Protection Officer" or Data Protection Officer;
Personal data: according to the LGPD, it is any information related to a natural person, directly or indirectly, identified or identifiable.
Sensitive personal data: is characterized by all information regarding racial or ethnic origin, religious conviction, political opinion, membership of a trade union or organization of a religious, philosophical or political nature, concerning health or sexual life, genetic or biometric data concerning to the natural person. To simplify the understanding, any data that may cause any embarrassment or prejudice about a natural person is considered sensitive personal data;
Holder: natural person to whom the personal data refer, such as potential customers, employees, contractors, business partners, third parties, etc;
Treatment: any operation realized with personal data, such as those referring to: the collection, production, reception, classification, use, access, reproduction, transmission, distribution, processing, archiving, storage, elimination, evaluation or control of information, modification, communication, transfer, diffusion or extraction;
Anonymization: process through which the data loses the possibility of association, directly or indirectly, with an individual, considering the reasonable technical means available at the time of treatment;
Cookies: a small computer file or data packet sent by a website to the user's browser when the user visits the website;
Pixel tags: are small blocks of code on a web page that allow websites to perform actions such as reading and placing cookies. The resulting connection may include information such as the person's IP address, the time the person viewed the pixel, and the type of browser in use;
Web beacons: is a technique used on web pages and e-mails to discreetly verify that a user has accessed some content. Web beacons are commonly used by third parties to monitor the activity of Holders on a website for the purposes of WEB analysis or page marking.
1). Purpose of the Privacy Policy:
This Privacy Policy and Personal Data Processing was developed to reaffirm the ethical commitment of the Tide Momentum website, represented by its management, employees and collaborators, with the aim of respecting and protecting the privacy of all its users in view of the validity of the General Data Protection Law - LGPD. Tide Momentum undertakes and takes all necessary care to comply with Law nº 13.709/2018 (General Data Protection Law) We have updated our Privacy Policy, in which we inform you which data we collect, how we use it and how we keep the information of the Holders safe and confidential.
Holders are the natural persons to whom the personal data refer, such as potential customers, actual customers, employees, contracted staff, business partners, service providers, suppliers and the general public (visitors), etc.
This Policy only applies to the institutional and promotional website Tide Momentum, a legal entity governed by private law, based in United States of America - USA, registered through the domain https://www.tidemomentum.com, subject to the provisions of the following clauses. This Policy outlines guidelines and requires all users to fully comply with them. Failure to comply with the rules may bring judicial and extrajudicial consequences. In this way, the Holders must read carefully this document before using the services offered by the Tide Momentum website, because by accessing it, the Holder declares that he is fully aware of the terms of this Privacy and Use Policy and fully accepts it, not being able to, in the future, claim that he did not know it.
The purpose of this Policy is to describe the guidelines and principles to ensure the protection of data subjects used on the Tide Momentum website, published under the domain https://www.tidemomentum.com, with worldwide operations, establishing rules regarding their rights and the processing and circulation of personal data in the company, in accordance with the General Data Protection Law (LGPD). This policy applies to Holders, that is, potential customers, actual customers, employees, contracted staff, business partners, service providers, suppliers and the general public (visitors), etc.
At any time, the Holders will be able to manage their personal information in order to always keep controlling of all of them.
2). Principles:
The basic principles and premises of this Privacy and Data Protection Policy comply with:
2.1. Ensure the protection of the holders of personal data;
2.2. Have clear and defined rules for the processing and circulation of personal data;
2.3. Ensuring that the personal data processing activities follow the observance of good faith and the following guidelines established in art. 6 of the LGPD:
• Finality;
• Adequacy;
• Necessity;
• Free access;
• Data quality;
• Transparency;
• Safety;
• Prevention;
• Non-discrimination;
• Responsability and accountability.
3). Guidelines of this Privacy Policy:
3.1. Update:
This Privacy Policy is dynamic, changed according to new schedules and / or features that may be implemented on this website or in new versions in the future. Therefore, periodic consultation is recommended. If the change is substantial and promotes a change in the data collection system of the Holders, the new conditions of the Privacy Policy will be informed through this page (Privacy Policy page). If the Holder has opted to receive communications from the company, he/she will receive notification by email. If changes are made to this Policy, it may take up to sixty (60) business days for new privacy practices to be implemented.
3.2. Which information/data we use:
The Tide Momentum website has a contact form. The Tide Momentum website does not have any kind of Cookies, Web Beacons, own / proprietary / private / primary Pixel Tags.
The contact form, located on the “Contact” Session, which requests the following information from Holders:
a). Name;
b). Email;
c). Subject matter;
d). Message.
In this way, the Tide Momentum website will only collect information actively entered by the Holder when completing these registration forms and through the contact form, located on the “Contact” Session. There is the collection of anonymized information automatically when exist direct access to the website and its pages by Google services, for example, incorporated into the website programming - which will be explained later in this Policy.
There is, therefore, the processing of two types of personal data: those provided by the Holder himself and those collected automatically by third-party services.
3.2.1. Personal data provided by the Holder: the Tide Momentum website collects all personal data entered or actively forwarded by the Holder through the registration forms and when contacting via the Contact Session, described above.
Regardless of what data the Holder actively provides to the company, the Tide Momentum website will only use those effectively relevant and necessary to achieve the declared objectives, on a case-by-case basis.
Completing the forms is optional and is not a requirement to browse the Tide Momentum website.
By using the services of the Tide Momentum website, the Holder authorizes that this data can be used to form part of a private database. This data will not be passed on to any individual or legal entity, under any circumstances, unless there is a request from the Judiciary, or for the purposes of criminal investigations (see item 3.5.).
3.2.2. Data collected automatically: a series of information is collected automatically through third-party services (AdOpt, Google Tag Manager, Google Analytics, Doubleclick.net, etc.), such as: characteristics of the access device, browser, IP (with date and time), IP origin, information about clicks, pages accessed, among others. These services incorporated into the website store cookies on activities arising from the browser (browser). However, this information only serves to define your privacy preferences (example: AdOpt), recognition and monitoring of actions for the generation of reports of statistical indicators of the website, in order to count accesses, demographic data, determine usage profiles, indicate which pages were visited, measure Holers' browsing time, among other applications (example: Google Analytics).
This type of collection is totally anonymized, preventing the direct identification of the Holders, that is, it is not possible to identify a Holder in any way, and there is no way for the Tide Momentum website to view and process any personal data that formally identifies a Holder.
Considering that all these cookies are managed by third parties, the user should consult the notifications and policies of the third party websites for more information.
The cookies used by the Tide Momentum website are categorized as:
3.2.2.1. Necessary: these cookies are necessary for the website to function and cannot be disabled, that is, they are always active. They are typically only set in response to actions that correspond to a request for services, such as setting your privacy preferences, logging in or filling out forms. The Holder may configure the browser to block or alert you about these cookies, but some parts of the website will not work. These cookies do not store any personally identifiable information. Example: Required: AdOpt and Google Tag Manager.
3.2.2.2. Performance: These cookies allow the Tide Momentum website to analyze visits and traffic sources, in order to measure and improve the website's performance. The reports help you to know which pages are the most and least popular, as well as understanding how visitors move during navigation. All information collected by these cookies is aggregated and therefore anonymous. If the Holder does not allow these cookies, we will not know when he visited our website. Example: Doubleclick.net (Google).
3.2.2.3. Statistics: collect information about how the user uses the website (which pages he visited). These cookies do not contain any information that can identify a Holder and They are only used to help improve and maintain the website, understand users' interests and measure the effectiveness of advertising. Example: Google Analytics.
3.2.2.4. Marketing / Advertising: these are cookies related to Google AdSense (Google Ads) and which do not identify a Holder's personal data.
Under any circumstances are cookies applied so that exist appropriation of personal or sensitive data, such as, but not limited to, your RG number, your CPF, physical address, passwords, bank details. The Tide Momentum website does not have or will have access to your email messages, open or not, and may not publish on your behalf. In this way, the Tide Momentum website does not capture and pass on any type of banking, economic, credit or debit card data or other information to any partner company or third parties. The Tide Momentum website or any marketing actions of the company may launch and disclose, in the future will never ask for this data at any time. Therefore, before providing them, the Holder must verify that he is really browsing the Tide Momentum website, if an email-marketing, SMS message, message via Whatsapp or any other means of communication comes from the company.
The Tide Momentum website does not about the general purposes said here, the datas are considered sensitive by Law nº 13.709/2019, understood as those related to racial or ethnic origin, religious conviction, political opinion, union membership or religious organization. , philosophical or political, data relating to health or sex life, genetic or biometric data, provided that the treatment is based on specific terms previously made available to the Holders, through their specific consent or based on express legal authorization.
In addition, the information collected may, with the Holder's consent, be used for advertising purposes, such as sending information about the company's brands, products, services, promotions and discounts, as well as publicizing events or conducting research related to your activities.
It is important to point out that it is possible to enable or disable, through the settings of your internet browser, the automatic collection of information through certain technologies, such as cookies and caches from these third-party services. That is, when accessing the Tide Momentum website, the Holder will be able to check which cookies are, accept or refuse them all or choose which ones can be activated or not. At any time, the Holder may review their preferences and accept or refuse the operation of a cookie again.
The Holder must be aware that, if these technologies are disabled, some features offered by the website, which depend on the treatment of said data, may not work properly.
Cookies are valid for a certain period of time. After the expiration date, they are automatically deleted. The Holders can also delete them by clearing cookies, tags, meta tags and other markers from the cache of the browser used. To know how to clear the cache of the main browsers, the Holder must identify the software (browser) used and perform a search on the websites of the developers. Examples of browsers / browsers: Mozilla Firefox, Google Chrome, Internet Explorer (Microsoft) Microsoft Edge, Safari (Apple), among others.
3.3. How we use the data:
The personal data processed by the company is intended for the management, administration, provision, expansion and improvement of services to the Holder, as well as the creation of new services and products to be offered to the Holders.
The Tide Momentum website may centralize the personal data collected, which may be used in other services related to all the company's brands, respecting the purposes and consent of the Holder, whenever required by law. In some cases, the company may also process personal data when necessary to comply with legal or regulatory obligations.
The Tide Momentum website may also process personal data based on its legitimate interest (or the legitimate interest of another company in the group), always within the limits of what is expected by the Holder, especially taking into account the existing relationship with the company, and never to the detriment of their interests, fundamental rights and freedoms.
3.4. Retention of personal data:
The Tide Momentum website will not retain the Holder’s personal data for longer than necessary for the purposes for which they were collected or otherwise processed, as set out in this Policy and for which the company has a valid legal basis. In any event, we will not retain it longer than permitted by local legal retention periods, except where:
• The use of the service by the Holder is active, that is, while the Holder uses the service and the payment of his subscription is effective;
• For purposes of auditing, security, fraud control and preservation of rights, the Tide Momentum website may keep the registration history and data of the Holders for a longer period, in the cases that the law or regulatory rule so establishes, to carry out accountability to the bodies of control, or to preserve the rights of the company that holds the Tide Momentum website or the data subject.
3.5. With whom we will share the data:
The Tide Momentum website and other legal entities belonging to the same economic group will not share the data of the Holders commercially or free of charge under any circumstances. The information collected through the pages or by contacting the Holders will only be shared in the following cases:
3.5.1. With other companies of the economic group belonging to the company Tide Momentum, incorporated or operating in USA, Brazil or in any country, which undertake to use the information for the same purposes indicated in this Policy.
3.5.2. With outsourced partner companies for the creation and development of marketing and communication actions and also with outsourced companies or IT professionals.
3.5.3. With authorities, government entities, by court order or by the request of administrative authorities that have legal competence for such a request or for the protection of the company's interests in any type of conflict, including lawsuits and administrative proceedings, among which:
• Comply with legislation that requires such disclosure;
• Investigate, prevent or take action related to suspected or actual illegal activities or to cooperate with public bodies or to protect national security;
• Execution of your contracts;
• Investigate and defend against any third party claims or allegations;
• Protect the security or integrity of services (e.g. sharing with companies that are experiencing similar threats);
• Exercise or protect the rights, property and safety of Autopoli and its affiliated companies;
• Protect the rights and personal safety of your employees, users or the public.
3.5.4. In the case of transactions and corporate changes involving the company, in the event of sale, purchase, merger, reorganization, liquidation or dissolution of the company, cases in which the transfer of information will be necessary for the continuity of services.
3.6. How we keep data safe:
The Tide Momentum website uses the appropriate and legally required ways to preserve the privacy of the personal data it collects from the Holders. In this way, it adopts precautions in compliance with the guidelines on safety standards established in Decree No. 8,771/2016, such as:
• Protection against unauthorized access to your systems;
• Authorization of access to persons previously established to the place where the information collected is stored;
• Employees or suppliers who come into contact with personal data undertake to maintain absolute confidentiality. The breach of confidentiality will result in civil liability and will be held accountable in accordance with Brazilian legislation;
• All sharing of personal data realized is to compose the best experience for Owners. In this way, sharing may occur between internal departments of the company, always under the supervision of the Data Protection Officer (DPO) or responsible department. Internal or external data sharing will follow secure information exchange protocols.
In addition to technical efforts, the Tide Momentum website also adopts institutional measures aimed the protecting personal data, preserving confidentiality, integrity and availability, in order to keep the policies and governance structure constantly updated.
It is important to note that although all technologies and efforts are adopted to preserve the privacy and data protection of the Holders, no transmission of information is completely secure, so the company cannot fully guarantee that all information received or sent is not targeted. unauthorized access, perpetrated through methods designed to improperly obtain information.
In the event of any type of leak or unauthorized access to the database, the Tide Momentum website will immediately issue a statement to the competent Authority, informing such episode and the leaked data, and will take all measures to minimize any type of damage that this fact may cause, trying to identify the cause of the fact and taking the police, judicial and possible administrative procedures, following exactly what determines the Brazilian Legislation. However, once public, it will not be possible to guarantee that these data and information cannot be improperly accessed.
The information collected from holders or that may be collected may change if there are changes in Brazilian laws, or if we have to comply with judicial or administrative orders from Official Bodies in Brazil, or if we believe it is necessary to update these policies. In this case, we will issue a notice on the website informing you of these changes.
The data may be transferred or opened if there is a request from a Brazilian authority, without prior notice to the Holder. We may still store other data if we identify abusive use of our services or any possible practice of crimes or disruption of our services, which may later be passed on to the competent authorities.
3.7. Data and information of minors:
Minors under 18 (eighteen) years old are not allowed to use the service, the forms contained on the Tide Momentum website, even with the authorization of their guardians. As there are no technical measures really able to identify with certainty who the users are, in case of use of false data, we will not be responsible for any damages.
3.8. Data subject rights:
In compliance with the applicable regulations, with regard to the processing of personal data, the company respects and guarantees to the Holder, the possibility of submitting requests based on the following rights:
• Confirmation of the existence of processing and access to data;
• Correction of incomplete, inaccurate or outdated data;
• Anonymization, blocking or elimination of unnecessary, excessive or treated data in violation of current legislation;
• Portability of your data to another service or product provider, upon express request by the Holder, in accordance with the regulation of the national authority, observing trade and industry secretsl;
• Deletion of data processed with the consent of the Data Subject, except in the cases provided for by law;
• Obtaining information about public or private entities with which data was eventually shared;
• Information about the possibility of not providing your consent, as well as being informed about the consequences, in case of refusal;
• Revocation of Consent.
With regard to the responsibility of the company, the management of information about a Holder's account is the responsibility of the Data Protection Officer. The Holder is aware that the deletion of his information with the company will imply the deletion of all his information and data.
The company will make every effort to fulfill such requests in the shortest possible time. However, justifiable factors, such as the complexity of the action requested, may delay or prevent your prompt response.
Finally, the Holder must be aware that his request may be legally rejected, either for formal reasons (such as his inability to prove his identity) or legal reasons (such as the request for the deletion of data whose maintenance is free exercise of the right by the company).
The Tide Momentum website features links to other external websites. The company is not responsible for the actions, contents, commercial policies, terms of use or privacy policies of external, third-party websites. It is up to the Holder to visit the Privacy Policy page of these external websites to learn about their definitions and guidelines.
3.9 Rectification, deletion and access to data:
Requests to delete data that may exist in our database will be answered within 72 (seventy-two) business hours of the request.
For data collected automatically, after expiry of the validity of the third-party cookies that we use, or if the Holder deletes these cookies from the browser, all the data collected will be lost immediately and there will be no possibility of being used or recovered.
At any time, a Holder may review the permissions.
4). Contact information:
The Data Protection Officer (DPO) is responsible for accepting complaints and communications from data subjects in relation to personal data, providing clarifications, receiving communications from the National Data Protection Authority (ANPD).
In case of additional questions or requests, the Data Protection Officer (DPO) of the Tide Momentum website should be contacted via the following email: hello@tidemomentum.com
Data holders may also have concerns or complaints directly to the National Data Protection Authority as provided in LGPD at https://www.gov.br/anpd/pt-br domain
We will take all possible measures so that we can respond to your inquiries as soon as possible.
5). Additional Information:
This Privacy Policy is governed, interpreted and executed in accordance with the Laws of the Federative Republic of Brazil.
If one or more provisions contained here is declared void or unenforceable, as long as it does not taint or nullify the entirety of this document, it will not affect the validity and application of the remainder, and the remaining unaffected will remain sound for all purposes.
6). Final dispositions:
Situations not provided for in this Policy will be resolved by the Executive Board and submitted to the Executive Board and/or Superintendence. It is the responsibility of the DPO (Data Protection Officer) to assess compliance with this Privacy Policy and Processing of Personal Data.
7). Validity:
This Privacy Policy and Processing of Personal Data comes into force immediately as of its publication, and must be reassessed annually or when necessary.