top of page
Pátio de contêineres

PRIVACY POLICY AND WEBSITE USAGE

  • For a better understanding of this document, in this Privacy Policy, the following definitions apply:

    Treatment agents: The controller and the operator.
    Anonymization: The use of reasonable and available technical means at the time of processing, through which data loses the possibility of direct or indirect association with an individual.

    National Authority: Public administration body responsible for ensuring,
    to implement and oversee compliance with this Law throughout
    the national territory.

    Database: A structured set of personal data, established in
    in one or more locations, in electronic or physical format.
    Consent: A free, informed, and unequivocal expression of will by which the
    The data subject agrees to the processing of their data.
    personal items for a specific purpose.

    Controller: A natural or legal person, governed by public or private law,

    who is responsible for decisions regarding the treatment of
    personal data.

    Anonymized Data: Data relating to a data subject who cannot be identified.
    considering the use of reasonable technical means and
    available at the time of your treatment.

    Personal Data: Information relating to an identified natural person.

    or identifiable.

    Sensitive Personal Data: Personal data concerning racial or ethnic origin, beliefs
    religious affiliation, political opinion, union membership, or
    an organization of a religious, philosophical, or political nature,
    data relating to health or sex life, genetic data
    or biometric, when linked to a natural person.
    Supervisor: Person designated by the controller and operator to act
    as a communication channel between the controller, the
    data subjects and the National Data Protection Authority
    Data Protection Authority (ANPD).

    Operator: Natural or legal person, governed by public or private law,
    which processes personal data on behalf of
    controller.

    Research Institution: An agency or entity of the direct or permanent public administration.
    indirect or non-profit private legal entity
    profitable, legally constituted under Brazilian law and
    with headquarters and legal domicile in the country, which includes in its mission
    institutional or in its social or statutory purpose
    basic or applied research of a historical nature,
    scientific, technological or statistical.

    Data Subject: Natural person to whom the personal data refers.

    They are subject to treatment.

    International Transfer of
    Data:

    Transfer of personal data to a foreign country or
    international organization of which the country is a member.
    Processing: Any operation performed with personal data, such as
    which refer to collection, production, reception,
    classification, use, access, reproduction,
    transmission, distribution, processing, archiving,
    storage, disposal, evaluation or control of
    information, modification, communication, transfer,
    diffusion or extraction.

    Shared Use of Data: Communication, dissemination, international transfer,
    interconnection of personal data or processing
    shared personal databases by agencies and

    public entities in the fulfillment of their
    legal competencies, or between these and private entities,
    reciprocally, with specific authorization, for one or
    more treatment options allowed by these
    public entities, or between private entities.

  • This Privacy Policy was drafted in accordance with Federal Law No. 12.965 of April 23, 2014 (Brazilian Civil Rights Framework for the Internet) and Federal Law No. 13.709 of August 14, 2018 (Brazilian General Data Protection Law).

    The website is committed to complying with the regulations set forth in the General Data Protection Law (LGPD) and to respecting the principles set forth in Article 6 of said law:

    I. Purpose: carrying out the processing for legitimate, specific, explicit purposes, informed to the data subject, without the possibility of subsequent processing in a manner incompatible with those purposes;

    II. Adequacy: compatibility of the processing with the purposes informed to the data subject, according to the context of the processing;

    III. Necessity: limiting the processing to the minimum necessary to achieve its purposes, encompassing relevant, proportionate, and non-excessive data in relation to the purposes of the processing.
    data;
    IV. Free access: guaranteeing data subjects easy and free access to information about the form and duration of processing, as well as the completeness of their personal data;
    V. Data quality: guaranteeing data subjects the accuracy, clarity, relevance, and timeliness of their data, in accordance with their needs and for the fulfillment of the purpose of its processing;
    VI. Transparency: guaranteeing data subjects clear, accurate, and easily accessible information about the processing and the respective data controllers, while respecting commercial and industrial secrets;
    VII. Security: use of technical and administrative measures suitable to protect
    personal data from unauthorized access and accidental situations or
    unlawful acts of destruction, loss, alteration, communication or dissemination;

    VIII. Prevention: adopting measures to prevent the occurrence of harm in
    by virtue of the processing of personal data;
    IX. Non-discrimination: impossibility of carrying out treatment for purposes
    Unlawful or abusive discriminatory practices;
    X. Accountability and reporting: demonstration, by the agent, of
    adoption of effective measures capable of proving compliance and
    compliance with personal data protection regulations and, including,
    effectiveness of these measures.

  • Who is responsible for decisions regarding the processing of personal data?

    The General Data Protection Law defines the controller, in its Article 5, item VI, as the natural or legal person, governed by public or private law, who is responsible for decisions regarding the processing of personal data.

  • Who performs the data processing (Operator)?

    The General Data Protection Law defines, in its Article 5, item VII, the operator as the natural or legal person, governed by public or private law, who processes personal data on behalf of the controller.

  • Who is responsible for acting as a communication channel between the controller,
    The data subjects and the National Data Protection Authority (Data Protection Officer)?

    The General Data Protection Law defines the data protection officer (DPO), in its Article 5, item VIII, as the person designated by the controller and processor to act as a communication channel between the controller, the data subjects, and the National Data Protection Authority (ANPD).

    Users may contact us via email at cibele.campos@cimexglobal.com to resolve any questions about this Privacy Policy or to obtain more information about data processing carried out in accordance with the LGPD (Brazilian General Data Protection Law).

  • What are the rights of the holder of personal data?

    The holder of personal data has the following rights, conferred by the General Data Protection Law (LGPD):

    • Right of confirmation and access (Art. 18, paragraphs I and II): This is the right of the data subject to obtain confirmation from the service as to whether or not personal data concerning him or her are being processed and, if so, the right to access his or her personal data.

    • Right of rectification (Article 18, item III): This is the right to request the correction of incomplete, inaccurate, or outdated data.

    • Right to restriction of data processing (Article 18, item IV): This is the right of the data subject to restrict the processing of their personal data, and they may demand the deletion of unnecessary, excessive, or unlawfully processed data.

    • Right to object (Art. 18, § 2): This is the right of the data subject to object, at any time, to the processing of data for reasons related to their particular situation, based on one of the grounds for exemption from consent or in case of non-compliance with the provisions of the General Law on the Protection of Personal Data.

    • Right to data portability (Article 18, item V): This is the right of the data subject to transfer their data to another service or product provider, upon express request, in accordance with the regulations of the national authority, respecting commercial and industrial secrets.

    • Right not to be subject to automated decisions (Art. 20): the data subject has the right to request a review of decisions taken solely on the basis of automated processing of personal data that affect their interests, including decisions intended to define their personal, professional, consumer and credit profile or aspects of their personality.

  • The use of certain company functionalities by the data subject.
    Personal data processing will depend on the handling of certain personal data, for example:

    • Full name;

    • Social name;

    • Date of birth;

    • CPF registration number;

    • Email address;

    • User location;

    • Access log.

  • The way your personal data is collected is indicated below:

    • Provided by the user;

    • Obtained by using the service;

    • Cookies;

    • Obtained by the access device, after user authorization.

  • DADO
    TRATAMENTO
    FINALIDADE
    Registro de acesso
    Processamento
    Segurança e Operação: O dado é necessário para manter o usuário logado e monitorar padrões de compra para sugestões de reposição.
    Localização do usuário
    Coleta / Avaliação/ Processamento
    Personalização e Logística: O dado é necessário para identificar o idioma, aplicar normas técnicas específicas do país e calcular o frete internacional (Landed Cost).
    Número de inscrição no CUIT / CUIL; RUT / RUC / NIT ; RFC ; CPF / CNPJ ; RNC / NITE
    Acesso / Armazenamento
    Identificação do usuário e Compliance: Obrigatório para a emissão de Notas Fiscais de exportação e habilitação; Emissão de documentos de exportação.
    Nome completo empresa
    Acesso / Armazenamento
    Identificação do usuário: Necessário para o cadastro na plataforma e emissão de faturas (Proforma e Commercial Invoice).
  • The user's personal data is never shared with third parties under any circumstances.

  • CIMEX GLOBAL is committed to implementing the technical and organizational measures.
    capable of protecting personal data from unauthorized access and situations of
    destruction, loss, alteration, communication or dissemination of such data.

    To ensure security, solutions will be adopted that take into account: appropriate techniques; implementation costs; the nature, scope, context and purposes of the processing; and the risks to the rights and freedoms of the user.


    The service uses encryption to ensure that data is transmitted securely and confidentially, so that the transmission of data between the server and the user, and vice versa, occurs in a fully encrypted manner.

    However, the service disclaims responsibility for the exclusive fault of third parties, such as in the case of hacker or cracker attacks, or the exclusive fault of the user, such as when they themselves transfer their data to a third party. The company also undertakes to notify the user within a reasonable timeframe should any such event occur.
    type of breach of security of your personal data that could cause you a high risk
    risk to your personal rights and freedoms.
    A personal data breach is a security breach that causes,
    accidental or unlawful destruction, loss, alteration, disclosure or access
    unauthorized personal data transmitted, stored or subjected to any other
    type of treatment.
    Finally, CIMEX GLOBAL undertakes to process the user's personal data.
    with confidentiality, within legal limits.

  • Cookies are small text files sent by the website to the user's computer.
    user and which are stored on it, with information related to browsing.
    from the website.

    Through cookies, small amounts of information are stored by the user's browser so that the service server can read them later. For example, data about the device used by the user, as well as their location and time of access to the website, may be stored.

    It is important to emphasize that not all cookies contain the user's personal data, as certain types of cookies may only be used to ensure the service functions correctly.

    Information stored in cookies is also considered personal data. All rules set forth in this Privacy Policy also apply to these cookies.

  • This version of this Privacy Policy was last updated on [date].
    date of its publication.

    The publisher reserves the right to modify these rules at any time, especially to adapt them to the company's evolution, whether by making new features available or by removing or modifying existing ones.


    This Privacy Policy may be updated due to any regulatory updates, which is why the user is invited to periodically consult this section.

bottom of page