Last updated: February 2024
The privacy and protection of personal data are essential to the Senior Group. They are practiced effectively in all our business processes, by all our employees, and in our relationships with all our customers, suppliers, third parties, service providers, and business partners.
Therefore, we have developed this Privacy Statement to present to data subjects how we handle and protect personal data and guarantee the rights related to privacy and data protection.
In addition to this Privacy Statement, the Senior Group maintains an internal Information Security and Data Protection governance program that includes the ongoing development and maintenance of an Information Security Policy and a Data Protection Policy.
We are the Senior Group, under CNPJ (National Register of Legal Entities) 80.680.093/0001-81, specialized in software for over 34 years in the market, with headquarters in Blumenau/SC.
In this Privacy Statement we comply with the privacy and data protection requirements set out in Law No. 13.709, of August 14, 2018 – General Data Protection Law.
The concepts, terms, and definitions we apply in this Privacy Statement are established in Art. 5 of Law No. 13.709, of August 14, 2018 – General Data Protection Law.
For the privacy and protection of personal data, the Senior Group complies with the following principles in this Privacy Statement and in its internal governance program for Information Security and Data Protection, following Law No. 13.709, of August 14, 2018 – General Data Protection Law:
At the Senior Group, we only process personal data once we have established a specific purpose and legal basis.
In our internal Information Security and Data Protection governance program, we have a detailed mapping of all the purposes and legal bases we use for processing personal data through our Record of Processing Activities (RoPA), including definitions of categories of data used, resources involved (information systems used, for example), transfers abroad and sharing with other companies.
Simply put, we process personal data in the following cases and on the following legal bases:
Purpose Case and Legal Basis | Personal Data | Sensitive Personal Data |
|---|---|---|
1. Administrative and operational processes for executing contracts signed with our clients. | X | |
2. Administrative and operational processes, when explicitly requested by clients through consent. | X | X |
3. Internal procedures of legitimate interest that allow us to serve clients at their request via contract or consent, always with the legitimate aim of better meeting the client’s interests. | X | |
4. Internal procedures for complying with legal obligations, according to the cases and requirements laid down by law. | X | X |
5. Situations related to credit protection, when thus identified, applicable, and always according to the law. | X | |
6. Situations related to our regular exercise of rights, when thus identified, applicable, and always according to the law | X | X |
7. Compliance with public policy requirements, when thus identified, applicable, and always according to the law. | X | X |
8. Compliance with requirements for research bodies, when thus identified, applicable, and always according to the law. | X | X |
9. Situations related to the protection of life, when thus identified, applicable, and always according to the law. | X | X |
10. Situations related to health protection, when thus identified, applicable, and always according to the law. | X | X |
11. Situations related to fraud prevention and security of the data subject, always in compliance with the fundamental rights and freedoms of the data subject. | X |
If you wish to receive detailed information on the purposes and legal bases specifically related to the processing of your personal data, please refer to section 12 of this Privacy Statement.
We only collect your data through our information systems and corporate channels duly approved by our data protection officer. In other words, the Senior Group does not collect personal data through any kind of personal resources (e-mail, WhatsApp, and others, for example) from its employees, suppliers, service providers, or business partners.
When we collect your data, we already have the definition of the specific purpose and legal basis for the data processing, duly designated in our Record of Processing Activities (RoPA), as mentioned in section 3 of this Privacy Statement.
We only collect strictly necessary data to fulfill the specific purpose defined in the Operations Register. The categories of data that may be collected, according to the need for each purpose, are:
At the Senior Group, we only store and access personal data through duly approved corporate resources and after defining the specific purpose and legal basis in our Record of Processing Activities (RoPA).
To protect the storage of and access to personal data, we use technical and administrative Information Security controls, which are outlined in our Information Security Policy and maintained through our internal information security and data protection governance program.
Personal data is stored strictly for the time necessary to fulfill its purpose and legal basis. After that, the data can be deleted, anonymized, or kept by establishing a new purpose and its respective legal basis, always in compliance with current legislation.
For more information on the storage and deletion of personal data, please refer to section 8 of this Privacy Statement.
Senior Group’s headquarters and internal operations take place in Brazil, but our suppliers, service providers and business partners may have headquarters and/or operations abroad. In these cases, we may need to transfer personal data abroad.
All the purposes and legal bases for transferring data abroad are duly mapped in our Record of Processing Activities (RoPA).
If you wish to receive detailed information about our transfers abroad specifically related to the processing of your personal data, please contact our Personal Data Officer as described in the “Contact Us” section of this Privacy Statement.
Other data processors, such as operators or controllers, may receive personal data shared by the Senior Group. In these cases, personal data will only be shared for specific purposes and on clearly defined legal bases.
All situations regarding sharing personal data with other controllers and operators are duly established in our Record of Processing Activities (RoPA).
We will only share data with other processing agents when we have a formal relationship with said agent that justifies such sharing. This formal relationship can be determined through a contract or terms, declarations, or agreements between the parties.
Personal data will only be shared through formal resources and channels made available by the Senior Group or the processing agents. Therefore, no data exchange will happen through resources or channels not agreed between the parties.
Only personal data strictly necessary for fulfilling the specific purposes assigned to the processing agent, whether operator or controller, will be shared.
Personal data is kept only for as long as is necessary to fulfill the purpose for which it was collected. After this purpose has been fulfilled, the personal data may be:
When we delete personal data, whether physical or logical, we do so in such a way that the data can no longer be recovered.
Some of our purposes, due to their particular characteristics, may have a specific retention period for personal data. In this case, this will be stated in our Record of Processing Activities (RoPA).
The Senior Group’s websites, systems, portals, and applications may use cookies and other types of digital traces. Digital traces can be of the following types:
All purposes and legal bases for the use of cookies and digital traces are defined in our Record of Processing Activities (RoPA).
We at the Senior Group are committed to planning, executing, and monitoring actions, to critical analysis, and to continuous improvement in an Information Security Management System. To this end, we use as a basis the guidelines set out in ABNT (Brazilian National Standards Organization) NBR (Brazilian Regulatory Standard) ISO/IEC 27001 – SGSI-Information Security Management System, together with Tracker Segurança da Informação’s information security management methodologies.
We keep an Information Security Policy (internal document) with the necessary and appropriate controls to guarantee the confidentiality, integrity, and availability of the information under our supervision.
We also work more directly at data privacy and protection management, based, in this case, on the precepts defined in ABNT NBR ISO/IEC 27701 – SGPI-Information Privacy Management System, together with Tracker Segurança da Informação’s data privacy and protection management methodologies.
We keep a Data Protection Policy (internal document) with the necessary and appropriate controls to guarantee the privacy and protection of personal data under our supervision.
The Information Security Policy and the Data Protection Policy, along with their derivative documents (specific policies, standards, and procedures), comprise our internal Information Security and Data Protection program, which is continuously monitored and updated in our company.
The following personal data subjects’ rights are preserved and duly made available by the Senior Group:
Should you wish to exercise your rights, whether those mentioned above or any others relating to privacy and the protection of personal data, please contact our Data Protection Officer, as outlined in section 12 of this Privacy Statement.
The Senior Group’s Data Protection Officer (DPO) is Mr. Jean Carlo Corrêa Gomes.
The contact for the Data Protection Officer, as well as the channel for requests about privacy and data protection, is encarregado@senior.com.br.
Should you wish to exercise any of your rights or receive detailed information specifically about the processing of your personal data, please contact our personal data protection officer.
The officer’s activities consist of:
We are continuously improving the privacy and protection of personal data. Therefore, this Privacy Statement may be updated at any time with immediate effect.
We recommend that you consult this privacy statement from time to time in order to keep up to date with the latest version available.
This Privacy Statement is in version 2.0, made available on December 29, 2022.
DUNS NUMBER: 678267460
Desenvolvido por Guide