Nextar Tecnologia de Software LTDA., registered under CNPJ number 04.580.911/0001-96, reaffirms its commitment to the protection of personal data processed within the scope of its activities, observing the General Data Protection Law (LGPD), the principles of purpose, adequacy, necessity, transparency, security, prevention, non-discrimination and accountability, as well as other applicable regulations.Privacy is an integral part of the relationship of trust maintained by Nextar with its clients, users, employees, candidates, suppliers, business partners, visitors to its digital channels, and other holders of personal data.
This Policy explains, in clear and accessible language, which categories of personal data may be processed, for what purposes, with whom they may be shared, how long they may be kept, what protection measures are adopted, and how data subjects may exercise their rights.
Nextar Tecnologia de Software LTDA., registered under CNPJ number 04.580.911/0001-96, reaffirms its commitment to the protection of personal data processed within the scope of its activities, observing the General Data Protection Law (LGPD), the principles of purpose, adequacy, necessity, transparency, security, prevention, non-discrimination and accountability, as well as other applicable regulations.
Privacy is an integral part of the relationship of trust maintained by Nextar with its clients, users, employees, candidates, suppliers, business partners, visitors to its digital channels, and other holders of personal data.
Nextar is a Brazilian technology and software development company, headquartered in Florianópolis/SC, that operates through a software-as-a-service (SaaS) model and a Product-Led Growth (PLG) strategy. Its main product is Nex, a solution focused on managing and integrating physical and digital sales for small and medium-sized businesses.
This Policy applies to the processing of personal data carried out by Nextar on its websites, institutional pages, forms, platforms, systems, applications, portals, APIs, integrations, customer service channels, communications, contracts, administrative processes, support activities, marketing, recruitment, employment relationships, physical security, and other interactions related to its operations.
Personal data may be provided directly by the data subject, received from clients, representatives, partners, suppliers, integrated systems, third-party platforms, legitimate sources, or generated during the use of products and services. The actual collection will depend on the type of relationship, the functionality used, the applicable contract, and the purposes described in this Policy.
This Policy does not replace terms of use, contracts, data protection addenda, specific notices, consent forms, privacy communications, or documents specific to a particular product, service, campaign, integration, or contractual relationship. These instruments should be interpreted in a complementary manner.
The organization responsible for this Policy is Nextar Tecnologia de Software LTDA., registered under CNPJ number 04.580.911/0001-96, with its administrative headquarters in Florianópolis/SC, hereinafter referred to simply as "Nextar".
Nextar acts as a Controller when it defines the purposes and means of processing personal data in its own activities, such as account and subscription management, commercial relationships, support, billing, marketing, recruitment, employee management, supplier contracting, information security, physical access control, video monitoring, and addressing the rights of data subjects.
Nextar may act as a Data Processor when processing personal data on behalf of clients and subscribers who use the Nex platform, including data from its own consumers, users, employees, or business contacts. In these situations, the client is, as a rule, the Controller responsible for decisions regarding the collection and use of data, and Nextar processes the data in accordance with the instructions received, the applicable contract, and the technical limitations of the solution.
The role of each party may vary depending on the activity, the product, the integration, the decision-making autonomy, and the instruments signed. Specific documents may detail responsibilities, instructions, security measures, sub-operators, transfers, and procedures for assisting data subjects.
Definition
Treatment Agents
Controller and Operator of personal data.
ANPD
Art. 7, The National Data Protection Agency is the authority responsible for ensuring, implementing, and overseeing compliance with the LGPD (Brazilian General Data Protection Law).
Consent
A free, informed, and unequivocal expression of consent by which the data subject agrees to the processing of personal data for a specific purpose.
Controller
Natural or legal person responsible for decisions regarding the processing of personal data.
Cookies
Files or similar technologies used on websites and digital channels for functionality, security, preferences, usage analysis, or other stated purposes.
Personal Data
Information relating to an identified or identifiable natural person.
Sensitive Personal Data
Data concerning racial or ethnic origin, religious beliefs, political opinions, trade union membership, health, sex life, genetic or biometric data relating to a natural person.
Data Protection Officer / DPO
Person designated to act as a liaison between the organization, data subjects, and the ANPD (Brazilian National Data Protection Authority), and to support privacy governance.
Operator
A natural or legal person who processes personal data on behalf of the Controller.
Holder
Natural person to whom the processed personal data refers.
Treatment
Any operation performed with personal data, such as collection, use, access, storage, sharing, alteration, deletion, or transfer.
International Transfer
Transfer of personal data to a foreign country or international organization, including through the use of global cloud services, support or technology.
Nextar may process the data categories below, by way of example. Not all data will be collected in all relationships, and collection should be limited to what is necessary for the applicable purpose.
Examples
Identification and registration
Name, CPF (Brazilian personal identification number), RG (Brazilian identity card number), date of birth, signature, nationality, and other identifiers necessary for registration or the contractual relationship.
Contact
Email, phone number, WhatsApp, home or business address, and contact preferences.
Professional and business data
Job title, area of expertise, company, brazilian company registration number (CNPJ), professional affiliation, business profile, industry, company size, and information on representatives or focal points.
Account, authentication, and permissions
Login, protected password, user identifier, access profile, permissions, tokens, login attempts, access date and time, and authentication information.
Using the Nex platform
Features used, settings, operational history, usage events, activity logs, product data, inventory, sales, and other information related to the use of the solution.
Data entered by customers
Personal data that customers and subscribers register on the platform, such as identification, contact information, purchase history, transactional or operational information of their own consumers, users, or employees. In this case, Nextar tends to act as an Operator.
Finance, billing and tax
Contracted plan, payment status, billing information, transaction identifiers, invoices, receipts, bank information when necessary, and tax documents.
Customer service and support
Messages, protocols, recordings (when provided), questions, requests, complaints, technical diagnoses, and service history.
Marketing and relationship
Commercial interest, origin of contact, interactions with campaigns, events, newsletters, surveys, communication preferences, and relationship records.
Navigation and device
IP address, browser, operating system, device identifiers, pages accessed, access origin, date and time, session logs, and technical data.
Logs, security and fraud prevention
Application and infrastructure logs, alerts, security events, lockouts, access attempts, audit trails, and evidence necessary for protecting environments.
Integrations and APIs
Identifiers, tokens, API records, data transferred, processing status, and communication logs between systems.
Suppliers and partners
Name, CPF, email, phone number, position, company, representation documents, contractual, banking, and tax information, and relationship history.
Candidates
Curriculum vitae, education, professional experience, salary expectations, evaluation results, interview information, and data provided during the selection process
Employees and service providers
Data related to hiring, employment, contracts, banking, compensation, benefits, work schedule, vacations, training, performance, leaves of absence, and termination.
Occupational health and sensitive data
Medical certificates, occupational health exams, sick leave records, health information necessary for compliance with legal obligations and, where applicable, other sensitive data processed with additional safeguards.
Biometrics, image and physical security
Images captured by cameras, traffic records, and facial biometric data used for access control, when applicable.
Aggregated or anonymized data
Statistics, indicators, metrics, and reports that do not allow for the direct identification of a person, when anonymization is effective.
Identifiers for advertising and audience
Email addresses and, where applicable, other contact information of subscribers or representatives who have a direct relationship with Nextar, used for customer correspondence, creation of custom or similar audiences, and campaign measurement. These identifiers may be subject to cryptographic hashing, without necessarily anonymizing them.
Sensitive personal data will receive restricted and proportionate treatment, with an appropriate legal basis, access controls, and additional security measures. When Nextar acts as an Operator, the content of the data entered on the platform will be determined by the respective Controlling client.
Nextar processes personal data for legitimate, specific purposes compatible with its activities. The legal basis may vary depending on the relationship, the data category, and the context of the processing.
Description
Legal basis
Related categories
Account registration and management
Create, maintain, and update user, client, and representative accounts; manage profiles, permissions, and settings.
Article 7, V and IX.
Identification; contact; account and authentication; professional data.
Provision of the platform and services
To enable the use of Nex, its functionalities, integrations, contracted resources, operational continuity, and service execution.
Article 7, V and IX.
Account; platform usage; integrations; operational data.
Handling cases on behalf of clients
Execute instructions from Controller clients and process data entered into the platform for the purposes defined by them.
Legal basis defined by the Controller; applicable contract and instructions.
Data entered by customers; operational data; integrations.
Authentication and security
Confirm identity, protect accounts, control access, prevent fraud, abuse, intrusions, and misuse.
Article 7, II and IX; Article 11, II, "g", when applicable.
Authentication; logs; device; biometrics; security events.
Customer service and support
Answer questions, handle calls, complaints, and technical requests, and follow up on problem resolution.
Article 7, items V and IX; Article 7, item II, when applicable.
Contact; support; account; logs; platform usage.
Contract management and relationship
Manage proposals, contracts, renewals, communications, focal points, and commercial obligations.
Article 7, V and IX.
Identification; contact information; professional details; relationship history.
Billing, invoicing and tax obligations
Process payments, collections, refunds, invoices, reconciliations, and accounting or tax obligations.
Art. 7º, V, II and IX.
Financial information; identification; contact details; contractual data.
Institutional communication and marketing
Sending content, updates, invitations, surveys, campaigns, and information about products and services, while respecting preferences and objections.
Art. 7, I and IX.
Contact; marketing; navigation; relationship.
Usage analysis and experience improvement
Evaluate journeys, errors, performance, functionalities, and metrics to improve products and services.
Art. 7, IX; consent, when required for non-essential technologies.
Platform usage; analytics; logs; aggregated data.
Development, testing and quality
Create, correct, test, approve, and maintain functionalities, prioritizing synthetic, anonymized, or minimized data whenever possible.
Article 7, V and IX.
Logs; technical data; integrations; aggregated data.
Information security and incidents
Monitor environments, detect threats, investigate events, record evidence, and respond to incidents.
Article 7, II, VI and IX; Article 11, II, "d" and "g", when applicable.
Logs; security events; account; device; integrations.
Compliance with legal and regulatory obligations
To meet tax, labor, social security, consumer, internet, data protection requirements, and directives from authorities.
Article 7, II; Art. 11, II, "a".
Registration, contractual, tax, functional, and sensitive data, as required.
Regular exercise of rights
Preserve evidence, respond to legal proceedings, audits, complaints, disputes, and defend the rights of Nextar or third parties.
Art. 7, VI; Art. 11, II, "d".
Data related to the event, contract, service, or dispute.
Supplier and partner management
Register, hire, pay, evaluate, and manage suppliers, integrators, consultants, and partners.
Art. 7º, V, II and IX.
Identification; contact information; professional, banking, tax, and contractual details.
Recruitment and selection
Receiving resumes, evaluating applications, conducting interviews, and building a talent pool when applicable.
Art. 7, V, IX and I, as applicable.
Candidate information; identification; contact information; professional data.
People management
Manage hiring, contracts, benefits, compensation, work hours, vacations, leaves of absence, training, and termination.
Article 7, V and II; Article 11, II, "a" and, when applicable, "f".
Functional data; financial data; dependents; occupational health.
Physical security and access control
To protect people, facilities, equipment, and property; to control entry and investigate physical events.
Article 7, IX and II; Article 11, II, "g", when applicable.
Image; circulation; biometrics; identification.
Customer service for policyholders
To receive, validate, analyze, and respond to requests related to the rights provided for in the LGPD (Brazilian General Data Protection Law).
Article 7, II and VI.
Identification; contact information; details related to the request.
Personalized advertising and campaign targeting
Creating custom audiences, performing customer matching, identifying lookalike audiences, excluding subscribers from inappropriate campaigns, and optimizing or measuring campaigns on paid media platforms such as Google Ads and Meta Ads. This activity should be limited to data from subscribers or representatives who have a direct relationship with Nextar, without using data entered by customers on the Nex platform for this purpose, unless otherwise instructed by the respective Controller.
Art. 7, I. Exceptionally, Art. 7, IX, through documented assessment of legitimate interest, need, holder's expectation, safeguards and effective opposition mechanism.
Contact information; professional and business details; identifiers for advertising and audience engagement; relationship history and communication preferences.
Nextar may use email addresses of its subscribers or representatives linked to the contracting colors to create custom audiences, perform customer matching, form lookalike audiences, optimize ad delivery, exclude people from certain campaigns, and measure results on digital advertising platforms, including Google Ads and Meta Ads.
For this purpose, identifiers may be sent directly through authorized interfaces or converted into codes using a cryptographic hash function, according to the capabilities of the platform used. The use of hashing constitutes a risk reduction measure, but does not constitute anonymization when the information can still be associated with the holder for matching purposes.
This processing will only be carried out on an appropriate legal basis, observing the principles of purpose, adequacy, necessity, transparency and security, and respecting the policies of the platforms involved. When the activity depends on consent, Nextar will seek to obtain it freely, informedly and unequivocally, allowing its revocation. When there is an assessment of legitimate interest, Nextar must document the balancing test, consider the expectations of the data subject, adopt safeguards and provide a simple objection mechanism.
Nextar will not use, for this purpose, personal data entered by customers on the Nex platform while acting as an Operator, nor sensitive personal data or data of children and adolescents. The mere inclusion of this information in the Policy does not replace the need to implement the controls, records and choice mechanisms required by applicable legislation.
Nextar may use more than one legal basis for the same activity when there are different data, data subjects, or purposes. When consent is used, it may be revoked, without prejudice to processing carried out previously and the legal grounds for data retention.
Nextar may share personal data only when necessary, in a proportionate manner and consistent with the applicable purpose. Sharing may occur with the following categories of recipients:
Purpose of sharing
Customers and Controllers
To perform the contracted services, enable access, follow instructions, provide support, and fulfill obligations stipulated in the contract.
Users and authorized representatives
To enable account usage, profile management, reporting, permissions, support, and service-related communications.
Cloud, hosting and infrastructure providers
For storage, processing, availability, monitoring, backup, security, and continuity of technological environments.
Software and technology providers
For authentication, communication, support, observability, analytics, management, development, integrations, and system protection.
Payment methods, banks and financial services
For billing, invoicing, reconciliation, fraud prevention, payment processing, and compliance with financial obligations.
Communication, CRM and marketing providers
For customer service, sending messages, campaigns, surveys, relationship building, and preference management, in accordance with applicable legal provisions.
Partners, integrators and developers
To operate integrations, APIs, complementary functionalities, and contracted or authorized projects.
Professional consulting and advisory services
For legal, accounting, tax, labor, audit, information security, privacy, and governance support.
HR, benefits and occupational health providers
For recruitment, payroll, benefits, occupational health and safety, and other human resources management activities.
Public authorities and regulators
To comply with legal obligations, decisions, orders, inspections, and legitimate requests from competent authorities.
Parties in corporate transactions
In reorganizations, mergers, acquisitions, investments, audits, or asset transfers, with appropriate safeguards.
Digital advertising platforms
With Google Ads, Meta Ads, and equivalent platforms, for customer matching, creation of custom or lookalike audiences, audience exclusion, optimization, measurement, and campaign analysis. Sharing must be limited to contact data obtained directly by Nextar, use authorized interfaces, and comply with the legal basis, the data subject's choices, and applicable policies.
When third parties process personal data on behalf of Nextar, they will be considered Operators or Sub-operators, depending on the context. Nextar will seek to establish obligations of confidentiality, security, purpose limitation, cooperation in incidents, assistance to data subjects, deletion or return of data, and other applicable conditions.
To enable paid media campaigns, Nextar may share email addresses or equivalent identifiers of subscribers and representatives with Google Ads and Meta Ads. The platforms may compare the received identifiers with their own databases to create custom audiences, reach lookalike audiences, exclude specific audiences, optimize ads, and generate campaign metrics. Nextar will seek to limit sharing to the minimum necessary and utilize the security mechanisms and interfaces provided by the respective providers.
Data subjects may revoke their consent, when that is the legal basis used, or exercise their right to object, when applicable. Upon receiving a valid request, Nextar will take reasonable steps to stop further mailings and request or promote the removal of the identifier from the lists under its management, without prejudice to the processing already carried out and the controls maintained by the platforms themselves.
Due to the use of cloud infrastructure, global technology providers, remote support, and international integrations, personal data may be stored, accessed, or processed outside of Brazil. In these situations, Nextar will seek to use mechanisms permitted by the LGPD (Brazilian General Data Protection Law) and ANPD (Brazilian National Data Protection Authority) regulations, such as compliance decisions, standard contractual clauses, specific clauses, global corporate rules, or other valid safeguards, as applicable.
The list of countries, suppliers, and mechanisms will be detailed after the completion of the RoPA (Record of Prior Authorization for Data Protection) and the inventory of operators and sub-operators.
Personal data will be kept for the period necessary to fulfill the stated purposes, comply with legal, regulatory or contractual obligations, ensure the security of the environments, prevent fraud, and exercise rights in a regular capacity. Specific retention periods will be reviewed after the completion of the RoPA (Record of Prior Authorization for Data Protection) and the Data Retention and Disposal Policy.
Retention criteria
Account, registration and contract
During the contractual relationship and for the period necessary to fulfill obligations and exercise rights after its termination.
Data entered by customers
As per the contract, instructions from the Controller client, account lifecycle, and technical requirements for deletion, export, or return.
Application access logs
As a rule, for a minimum period of 6 months, when the Brazilian Civil Rights Framework for the Internet applies, without prejudice to longer periods as determined by law or legitimate grounds.
Tax and billing documents
For the legally applicable period, generally not less than 5 years, depending on the nature of the document and tax legislation.
Customer service and support
As needed for resolution, operational history, quality, safety, and the exercise of rights.
Marketing and communications
Until consent is revoked, objection is raised, the user unsubscribes, or the purpose is terminated, except in cases where necessary evidence is presented.
Candidates
During the selection process and, when justified, for the period specified for the talent pool.
Labor and social security data
Within the applicable legal timeframes, which may vary depending on the obligation and can extend to extended periods.
Occupational health
For the periods required by legislation and occupational health and safety standards, including up to 20 years after termination in applicable cases.
Biometrics, images, and access control
For the time necessary for physical security, investigation of events, and the purpose of the control, according to a timeframe to be formalized after the RoPA (Report of Apprehension and Control).
Logs and security
Depending on the risk, purpose of monitoring, investigation, fraud prevention, and legal or contractual obligations.
Backups
In accordance with technical retention, overwriting, and disposal cycles, respecting the rules applicable to the main data.
Anonymized data
They may be kept indefinitely when anonymization is effective and there is no reasonable possibility of re-identification.
Custom audiences and paid media
While the purpose, campaign, or applicable legal basis remains in effect, lists will be periodically reviewed. Identifiers must be removed or cease to be updated when consent is revoked, a valid objection is raised, the purpose is terminated, or the relationship ends, except for the minimum records necessary to demonstrate preferences, exclusions, and compliance.
At the end of the applicable period, the data may be deleted, anonymized, blocked, or securely archived, except when retention is permitted or required by law.
Nextar's digital channels use cookies, pixels, tags, identifiers, and similar technologies to enable the operation of the environments, enhance security, understand channel usage, and, with consent, measure campaigns and present advertising related to products and services.
Strictly necessary cookies are used to enable navigation, maintain security, record preferences, and provide requested functionalities. When they are essential for the channel's operation, their use will not require consent.
Analytical cookies help Nextar understand page performance, the origin of accesses, browsing journeys, errors, and the most used functionalities. Advertising cookies allow us to attribute conversions, measure campaigns, limit ad repetition, and perform remarketing or targeting actions.
Functional cookies and third-party technologies may remember choices, enable forms, display embedded videos, and allow integrations with external services. When not strictly necessary, analytical, advertising, and functional cookies should only be activated after prior, free, informed, and unequivocal consent from the user.
Continued browsing, silence, or lack of interaction with the cookie notice will not be interpreted as consent. Refusal of non-essential cookies will not prevent access to essential functionalities, although certain personalized features or third-party content may become unavailable.
The inventory below presents the main technologies identified in Nextar's channels. The list may be updated after additional technical verifications, supplier changes, or changes in available functionalities. The indicated timeframes may be reduced by browser, device, or provider settings.
Cookie / technology
Provider
Purpose
Duration
Strictly necessary
Cookie preferences and consent
Nextar or consent management platform
To record user choices, apply preferences, and prevent unnecessary repetition of the message.
Up to 1 year
Technical management
Google Tag Manager (GTM-T3N4WHS)
Manage and condition the activation of tags according to registered preferences and channel configuration.
It has no fixed duration; it depends on the tags that are triggered.
Analytical
_ga and _ga_<ID>
Google Analytics 4
To distinguish users, maintain session state, and produce usage and performance metrics.
Up to 2 years
Analytical
_gid (when used)
Google Analytics
To distinguish users for short-term statistical analyses.
24 hours
Advertising professionals
_gcl_au
Google Ads
Link and attribute conversions related to advertising campaigns.
Generally, up to 90 days, depending on the configuration.
Advertising professionals
_gcl_aw / _gac_*
Google Ads
Retain click identifiers and support the measurement of conversions across pages or domains.
Generally, up to 90 days, depending on the configuration.
Analytics and marketing
__trf.src / rdtrk (when active)
RD Station
Identify the origin of the visit and the lead's journey in the integrated forms and pages.
Up to 1 year
Third-party content
Embedded YouTube and equivalent integrations
Google/YouTube and other providers
Display embedded content and process interactions related to the requested feature.
Depending on the technology activated and the user's preferences.
The technologies may collect IP address, browser, operating system, device or session identifiers, pages accessed, access origin, date and time, interactions, conversion events, and other technical information. This data may be pseudonymized and should not necessarily be considered anonymous.
Google, RD Station, YouTube, and other providers may process data according to their own policies and, depending on their infrastructure, in other countries. In these cases, Nextar will seek to adopt the international data transfer mechanisms and safeguards provided for in the LGPD (Brazilian General Data Protection Law) and applicable regulations.
Users can accept all cookies, refuse non-essential cookies, or select specific categories through the banner or preference panel available on Nextar's channels. These choices can be changed or revoked at any time via the "Cookie Settings" option, without prejudice to any previously valid data processing.
Browser or device settings can be used as a supplementary measure to block, limit, or delete cookies. However, these settings do not replace the choice mechanisms provided by Nextar. Questions or requests related to cookies can be sent to the email address dpo@nextar.com.br.
Nextar's products and channels are generally aimed at people who work in business activities and are not intended for independent use by children.
It is possible for platform clients to enter data related to children or adolescents into their own transactions. In such cases, the client will be responsible for defining the purpose, the legal basis, the information provided to guardians, and the measures necessary to ensure the best interests of the child, while Nextar will act in accordance with the Controller's instructions and the applicable contract.
When Nextar processes data from children or adolescents on its own, it will seek to observe their best interests, limit data collection to what is necessary, adopt appropriate security measures, and obtain specific and prominent consent from at least one parent or guardian when this is the legally required basis, without prejudice to other cases provided for by law.
In cases where Nextar acts as a Controller, the data subject may request the exercise of the rights provided for in the LGPD (Brazilian General Data Protection Law). When Nextar acts as a Processor, the request may be forwarded to the responsible Controller client, with Nextar's cooperation within the limits of the contract and the instructions received.
How does it apply?
Confirmation and access
To confirm the existence of data processing and obtain access to personal data, respecting legal limits, trade and industrial secrets, and the rights of third parties.
Correction
Request the correction of incomplete, inaccurate, or outdated data.
Anonymization, blocking, or deletion
Request action regarding unnecessary, excessive, or improperly processed data in accordance with the LGPD (Brazilian General Data Protection Law).
Portability
Request number portability, when applicable and in accordance with ANPD regulations.
Information about sharing
Obtain information about public and private entities with which the data has been shared.
Consent
To receive information about the possibility of not consenting, revoking consent, and requesting the deletion of data processed on this basis, except in cases where legal retention is required.
Opposition
To object to processing based on the assumption that consent cannot be dispensed with when there is a breach of the LGPD (Brazilian General Data Protection Law).
Review of automated decisions
Request a review of decisions made solely on the basis of automated processing that affect your interests, where applicable.
Petition and complaint
Submit a petition to the ANPD (National Data Protection Authority) or consumer protection agencies, in accordance with legal requirements.
Regarding personalized advertising and audience creation on paid media platforms, the data subject may request information, revoke consent, where applicable, or object to the processing. Nextar may also maintain a suppression list with the minimum data necessary to respect the data subject's preference and prevent their re-inclusion in future campaigns.
Nextar adopts and improves technical, administrative, and organizational measures designed to protect personal data against unauthorized access, destruction, loss, alteration, communication, leakage, or any form of inappropriate or unlawful processing, considering the nature of the information, the risks, and the state of technology.
● Identity, access, and permission management as needed;
● Recording and monitoring of security logs and events;
● Authentication controls, confidentiality, and credential protection;
● Use of cloud infrastructure and security features compatible with the operation;
● Contracts and confidentiality agreements with employees, service providers, and suppliers;
● Incident response, investigation, and recording procedures;
● Business continuity, recovery, and backup measures as per applicable systems;
● Awareness campaigns, review of controls, and continuous improvement of the privacy and security program.
No security measure is foolproof. In the event of an incident that poses a significant risk or harm to data subjects, Nextar will assess the appropriate containment, correction, recording, and communication measures, including to the ANPD (Brazilian National Data Protection Authority) and to data subjects when required by law.
Access to Nextar's websites, forms, pages, portals, platforms, applications, APIs, and other digital channels must be lawful, ethical, and secure. Users must provide truthful information, protect their credentials, and use the environments only for authorized purposes.
Description
Unauthorized access
Attempting to access restricted accounts, systems, data, APIs, functionalities, or areas without authorization.
Malicious content
Inserting, transmitting, or disseminating viruses, malware, scripts, commands, or files that compromise environments.
Use of third-party identity
Providing false information, using third-party data without authorization, or impersonating someone else.
Interference and abuse
Overloading, damaging, rendering unavailable, altering, or interfering with the operation of channels and integrations.
Unauthorized automated collection
Performing scraping, mass extraction, or using robots, crawlers, or scrapers without express authorization.
Violation of rights
Using the channels for illegal, fraudulent, or abusive purposes, or in ways that violate privacy, intellectual property, confidentiality, or the rights of third parties.
The channels may contain links or integrations with third-party environments, subject to the policies, terms, and practices of each responsible party. Nextar does not fully control these environments and recommends reading the applicable documents before providing personal data.
Trademarks, content, layouts, codes, databases, materials, and other elements of digital channels are protected by intellectual property rights held by Nextar or authorized third parties.
In compliance with Article 41 of the LGPD (Brazilian General Data Protection Law), Nextar has appointed a Data Protection Officer to act as a communication channel with data subjects and the ANPD (National Data Protection Authority), and to support internal guidance on privacy and data protection.
Channel
Data Protection Officer / DPO
GEP Compliance Solutions – Represented by Maurício Rotta
E-mail
dpo@nextar.com.br
Nextar may update this Policy to reflect changes in products, services, technologies, suppliers, business models, security practices, legal requirements, regulatory decisions, international transfers, retention, cookies, or other aspects related to the processing of personal data.
The current version should be made available through the applicable institutional channels. Significant changes may be communicated through additional means, depending on the nature of the change and the relationship maintained with the data subject.