This Policy sets out the guidelines adopted by Voidr for the processing of Personal Data, ensuring it is carried out lawfully, transparently and securely, in compliance with Applicable Law and with the controls set out in the ISO/IEC 27001 standards.
| Version | Date | Prepared by | Approved by | Content |
|---|---|---|---|---|
| 00 | 2026-04-13 | Nathalia | Milson | Initial release of the document |
| 01 | 2026-05-14 | Nathalia | Milson | Restructuring and alignment |
This Policy sets out the guidelines adopted by Voidr for the processing of Personal Data, ensuring it is carried out lawfully, transparently and securely, in compliance with Applicable Law and with the controls set out in the ISO/IEC 27001 standards.
The purposes of this Policy are to:
This Policy must be observed by all Employees, across every area of Voidr that may have access to information, systems and Personal Data processed by Voidr.
It applies to all Personal Data processing activities carried out by Voidr, including:
This Policy must be observed together with the Information Security Policy and the Retention and Disposal Policy (POL-04).
Voidr collects Personal Data directly from Data Subjects (through forms, registrations and interactions on its platforms) and automatically (usage, device and telemetry data). Where applicable, it may also receive data from public sources or partners.
Personal Data is used to:
Each processing activity will be carried out on one of the legal bases set out in the LGPD (Brazilian General Data Protection Law), according to the data category and the purpose.
Voidr acts as Controller in relation to the Personal Data of its Employees, corporate customers and users of its commercial platforms.
Voidr acts as Processor in relation to Personal Data processed on behalf of its customers in the performance of contracted services, following the Controller's instructions as to purpose, retention periods and other processing conditions. In self-hosted mode, the data remains entirely within the customer's infrastructure.
Voidr may share Personal Data with:
International transfers will only be carried out with adequate safeguards in place, such as Standard Contractual Clauses, pursuant to article 33 of the LGPD.
In accordance with the LGPD, Data Subjects have the right to:
Requests must be submitted to the DPO and answered within 15 (fifteen) calendar days, unless specific legislation sets a different deadline. Where Voidr acts as Processor, requests are forwarded to the Controller, with the support necessary to fulfil them.
Voidr adopts technical and administrative measures to protect Personal Data against unauthorised access, loss, alteration or improper processing, including:
Retention periods and disposal procedures for Personal Data follow the Retention and Disposal Policy (POL-04). Once the retention period ends or the purpose of processing has been achieved, Personal Data will be securely deleted or irreversibly anonymised.
Any Employee who becomes aware of a security incident involving Personal Data must immediately notify the DPO through the channels listed in item 13.
The DPO will lead the investigation and, depending on severity, will notify the ANPD, the affected Data Subjects and, where Voidr acts as Processor, the relevant Controller, within the deadlines and in the manner set out in the applicable regulations.
This Policy takes effect on the date of its publication, for an indefinite term, and may be amended by Voidr at any time, subject to the version control process set out in item 3.
This Policy must be reviewed at least annually, or whenever there are relevant changes to data processing activities, to applicable legislation, or as a result of internal and external audits.
A copy of this Policy will be made available through Voidr's Google Drive and on the Official Website, controlled in accordance with the Master List, following notification of additions and changes by email to the Employees involved.
For clarifications, requests or to exercise your rights, please contact Voidr's Data Protection Officer:
DPO: Fabiano Kenzo
Deputy DPO: Nathalia
Address: São Paulo, SP, Brazil
If a satisfactory response is not received, the Data Subject may escalate the matter to the ANPD (Brazilian National Data Protection Authority).