Privacy and Data Protection Policy
1. INTRODUCTION
Coaktion’s purpose is to simplify the complexity of digital transformation and elevate the customer experience. We know that trust is the foundation of any relationship and, for that reason, we are committed to ensuring the privacy and protection of the personal data collected and processed across our group of companies (Aktie Now, Callwe, Droz, Workise and Syntrika).
This Policy meets the requirements of the applicable data protection laws, including Brazil’s General Data Protection Law (LGPD), the European Union’s General Data Protection Regulation (GDPR) and United States privacy legislation (such as the CCPA/CPRA), and is aligned with international best practices for privacy management (ISO/IEC 27701) and information security (ISO/IEC 27001 and 27002).
Questions regarding the applicable legislation and/or processes involving the collection or use of Personal Data must be directed to Coaktion’s Data Protection Officer (DPO) exclusively through the official channel:
- E-mail: dpo@coaktion.com
2. DEFINITIONS
For the purposes of this Privacy and Personal Data Protection Policy (the “Policy”), the terms and expressions used shall have the meanings set out below:
- Applicable Data Protection Laws: refers to all privacy and personal data protection legislation in force in the jurisdictions where Coaktion operates, including the LGPD (Brazil), the GDPR (European Union) and United States state privacy laws.
- Information Security and Compliance Committee: a committee formed by Coaktion employees whose role is to support Coaktion’s directors and its Data Protection Officer (DPO) in decisions concerning the group’s Information Security Management System and Privacy and Data Protection Management System;
- Personnel: includes employees, partners, service providers and any other person with a direct relationship with the company;
- Data Subject: the natural person to whom the personal data being processed relates;
- Personal Data: data relating to a natural person that allows, in any way (directly or indirectly), their identification;
- Sensitive Personal Data: personal data concerning racial or ethnic origin, religious belief, political opinion, membership of a trade union or of a religious, philosophical or political organisation, data concerning health or sex life, genetic or biometric data, as well as other specific data deemed sensitive under applicable laws and regulations;
- Direct Data: data that refers directly to a specific data subject without the need for additional information to identify them;
- Indirect Data: data that cannot be attributed to a data subject without the use of additional information to identify them;
- Pseudonymised Data: data processed using techniques that mask its attribution to a data subject, while remaining possible to revert the data to its original state;
- Anonymised Data: data relating to a data subject that does not allow their identification through reasonable technical means available at the time of processing; Processing Agents: refers to the Controller and the Processor;
- Data Controller: a natural or legal person, governed by public or private law, responsible for decisions concerning the processing of personal data;
- Data Processor: a natural or legal person, governed by public or private law, that processes personal data on behalf of the Controller;
- Data Protection Officer or DPO: the person appointed by the Controller and/or Processor to act as the communication channel with data subjects and the competent Supervisory Authorities.
- Processing: any operation carried out with personal data, such as collection, production, receipt, classification, use, access, reproduction, transmission, distribution, processing, filing, storage, deletion, evaluation or control of the information, modification, communication, transfer, dissemination or extraction of personal data;
- Purpose: carrying out processing for legitimate, specific and explicit purposes that are communicated to the data subject, with no possibility of subsequent processing incompatible with those purposes;
- Necessity: limitation of processing to the minimum required to achieve its purposes, covering data that is relevant, proportionate and not excessive in relation to the purposes of the processing;
- Consent: the free, informed and unambiguous statement by which the data subject agrees to the processing of their personal data for a determined and specific purpose;
- Legal Basis: the justifications used to legitimise the processing of personal data;
- Cookies: considered identifiers, that is, they are generated and collected through the browser for the purpose of identifying a browsing profile or facilitating access to a web page;
- Record of Processing Activities (ROPA): documentation describing how personal data processing activities are carried out;
- Data Protection Impact Assessment (DPIA): documentation describing personal data processing operations that may create risks to the civil liberties and fundamental rights of the data subject, as well as the measures, safeguards and risk mitigation mechanisms adopted;
- Supervisory Authority: the public administration body or governmental entity responsible for overseeing compliance with data protection laws (such as the ANPD in Brazil or the Data Protection Authorities — DPAs — in Europe);
- Privacy by Design: the principle establishing that privacy and data protection must be embedded in the design and architecture phase of any new system, product or process.
- Privacy by Default: the principle ensuring that, by default, only the personal data strictly necessary for each specific purpose is processed.
3. PURPOSE
To define the guidelines and rules applicable to the Processing of Personal Data across the Coaktion ecosystem, ensuring an adequate level of protection, transparency and compliance with the Applicable Data Protection Laws and with the regulations issued by the Supervisory Authorities. This Policy guides the conduct of all personnel and partners, ensuring that data subjects’ rights are respected and that privacy risks are mitigated pragmatically and continuously.
4. APPLICABILITY AND SCOPE
This Policy applies to all companies in the Coaktion ecosystem (Aktie Now, Callwe, Droz and Workise), covering all personnel, service providers, suppliers and business partners who use the processing environment and/or have access to information belonging to Coaktion or its Clients.
The scope of this Policy covers all forms of processing, whether automated or manual, and recognises that Coaktion acts in two distinct capacities under the Applicable Data Protection Laws:
Coaktion acts as a Data Controller when it makes the decisions concerning the processing of personal data. This occurs in internal and administrative processes, such as:
- Recruitment, selection and management of employees and service providers;
- Engagement of suppliers and business partners;
- Coaktion’s own marketing, sales and commercial relationship activities;
- Compliance with legal, labour and regulatory obligations.
Coaktion acts as a Data Processor when it processes personal data on behalf of and according to the instructions of its Clients (who are the Controllers of the data). This is the primary role of our ecosystem in the services we provide, such as:
- Implementation and support of partner platforms (e.g. Zendesk, Salesforce, monday.com) carried out by Aktie Now and Workise;
- Processing of voice and communication flows through the Callwe platform;
- Interactions, automations and AI-guided customer service through the Droz platform.
In these cases, Coaktion will apply the guidelines of this Policy together with the contractual terms agreed with each Controller Client, ensuring the technical and organisational security of the operations.
This Policy has global reach. Should any conflict arise between the guidelines set out herein and the local laws of a specific jurisdiction where Coaktion operates, the rule offering the highest level of protection to the data subject shall prevail.
5. PRIVACY PRINCIPLES AND GUIDELINES
The Processing of Personal Data under the responsibility of the Coaktion ecosystem is carried out in strict compliance with the Applicable Data Protection Laws, based on the following organisational principles and guidelines:
i) Purpose and Necessity: The collection and processing of data must have legitimate, specific and disclosed purposes. We process only the data strictly necessary (least privilege) to achieve business purposes or to perform contracts.
ii) Privacy by Design and by Default: The development of new products (such as Droz’s AI solutions) and the implementation of client projects (Aktie Now and Workise) must consider data protection from the initial architecture onwards, ensuring that the highest level of privacy is the system default.
iii) Transparency and Free Access: We guarantee data subjects clear and accessible information about the processing carried out and the respective agents involved.
iv) Security and Prevention: We implement rigorous technical and organisational controls (described in our General Information Security Policy — PGSI) to protect data against unauthorised access, destruction, loss, alteration or leakage.
v) Legal Bases: No personal data is processed without a valid legal basis, as defined by the legislation of each jurisdiction (e.g. Articles 7 and 11 of the LGPD, Article 6 of the GDPR, or the applicable sections of the CCPA/CPRA).
6. ENGAGEMENT OF PROCESSORS (SUB-PROCESSORS)
As a technology ecosystem, Coaktion uses cloud infrastructure and third-party platforms to support its operations and the provision of services to its clients. Therefore:
Use of Sub-processors: Coaktion subcontracts technology services (such as cloud computing providers and SaaS platforms) that act as sub-processors in the processing of data.
Due Diligence and Compliance: The selection of any sub-processor is subject to prior assessment (due diligence). We contractually require our sub-processors to adopt technical and organisational information security measures compatible with this Policy, with the Applicable Data Protection Laws and with the ISO 27001 and 27701 standards.
Transparency towards the Controller: Where Coaktion acts as a Processor, the list of global sub-processors used in the provision of the service is made available to our Clients (Controllers) and is governed by the respective service agreements and contracts.
7. INTERNATIONAL TRANSFERS
Due to the global nature of the cloud services and partner platforms used across our ecosystem (e.g. hosting providers, CRM and process management systems), Coaktion carries out international transfers of personal data.
To ensure the lawfulness and security of these operations, Coaktion undertakes to carry out international transfers exclusively in the following cases (in accordance with the guidelines of the competent Supervisory Authorities, such as the ANPD in Brazil or the European Commission):
i) To countries or international organisations that provide an adequate level of personal data protection, as recognised by the competent authorities;
ii) Through the use of valid contractual safeguards, such as Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs) or duly issued compliance seals and certifications.
iii) Coaktion ensures that international partners provide technical security safeguards equivalent to those required by the Applicable Data Protection Laws.
8. RIGHTS OF PERSONAL DATA SUBJECTS
Coaktion guarantees Data Subjects the full exercise of their rights, as provided for in the Applicable Data Protection Laws (such as Article 18 of the LGPD, Chapter III of the GDPR and United States regulations). Every request received will be reviewed by the Data Protection Officer (DPO) and answered within the applicable statutory deadlines. The rights guaranteed include:
i) Confirmation of the existence of processing and facilitated access to the data;
ii) Correction of incomplete, inaccurate or outdated data;
iii) Anonymisation, blocking or deletion of unnecessary or excessive data, or data processed in breach of the law;
iv) Portability of the data to another service or product provider, upon express request;
v) Deletion of personal data processed on the basis of the data subject’s consent (except where legal retention applies);
vi) Clear information about the public and private entities with which the controller has shared data;
vii) Information about the possibility of withholding consent and the consequences of refusal, as well as the right to withdraw it.
viii) The right to opt out of the sale or sharing of personal data, as applicable under United States state privacy legislation.
9. COOKIES AND TRACKERS
On its portals, platforms and web applications, Coaktion may use cookies and identifiers (first-party or third-party) to optimise the user experience, ensure page performance, and for analytics and marketing purposes.
- The detailed guidelines, as well as the categories of cookies used and how the data subject can manage them, must be publicly described in the specific Privacy and Cookie Notice of each Coaktion website.
- Coaktion ensures the implementation of consent management tools (cookie banners) on its portals, allowing users to make clear choices about their use.
10. DATA RETENTION
In line with the principles of necessity and adequacy, Coaktion will retain Personal Data and Sensitive Personal Data only for the period strictly required to achieve the specific purposes for which it was collected.
- The retention period will observe the legal, regulatory, tax and contractual obligations applicable to our business, or the period strictly necessary for the regular exercise of rights.
- The specific retention periods for each process will be mapped, assessed and documented in our Record of Processing Activities (ROPA), ensuring that, once the purpose has been fulfilled or the statutory period has elapsed, the data is securely deleted or anonymised.
11. RECORD OF PERSONAL DATA PROCESSING ACTIVITIES (ROPA)
In compliance with the Applicable Data Protection Laws (such as the LGPD in Brazil) and with good governance practices, Coaktion maintains a duly documented and up-to-date record of its personal data processing activities (ROPA).
- To ensure greater organisation and security during audits, each business unit in the ecosystem (Coaktion, Aktie Now, Callwe, Droz, Workise and Syntrika) will maintain its own ROPA, reflecting the specific characteristics of its services and its role as Data Controller or Data Processor.
- The management, technical support and periodic validation of these records will be centralised with the Data Protection Officer (DPO) and/or Coaktion’s corporate Privacy function.
12. DATA PROTECTION IMPACT ASSESSMENT (DPIA)
Coaktion carries out privacy risk assessments to identify potential impacts on the rights and civil liberties of data subjects.
- Producing a DPIA is mandatory across all group companies before implementing new processes, projects, systems or policies involving high-risk data processing, emerging technologies (such as Artificial Intelligence) or Sensitive Personal Data.
- The document must describe the necessity and purpose of the processing, the data flows, the risks identified, the proposed solutions and the safeguards adopted.
- Any residual risks identified that are not immediately mitigated must be formally recorded and submitted to Senior Management for risk acceptance.
13. ACTIONS FOR IMPLEMENTING THE POLICY
Awareness and Culture: Coaktion will ensure the continuous delivery of a privacy and data protection education programme for all its personnel and service providers. The importance of the subject will be reinforced in day-to-day operations, from onboarding through to annual training, whose guidelines and effectiveness metrics are detailed in our Information Security Culture and Awareness Policy.
The Data Protection Officer (DPO): Coaktion will appoint a Data Protection Officer (DPO), who will be responsible for coordinating the operational actions required to implement the privacy strategy, monitoring compliance with the Applicable Data Protection Laws and acting as intermediary for official communication between Data Subjects, the organisation and the competent Supervisory Authorities.
- The DPO’s contact details will be centralised and readily accessible through Coaktion’s official channels and Privacy Notices.
Privacy and Personal Data Protection Committee: To support the DPO in the management, strategic decision-making and oversight of the Privacy Programme, Coaktion establishes a multidisciplinary Committee. The Committee will be composed of strategic representatives from the business, technology and operations units, ensuring that privacy decisions are practicable and do not create unnecessary friction in the services provided by the ecosystem.
Technical Measures and Audits: Coaktion will adopt robust technical and organisational policies and resources to prevent, detect and monitor potential breaches of the LGPD. The implementation of this Policy and of the resulting actions will be subject to continuous monitoring and periodic internal audits, ensuring compliance with ISO 27701.
14. CONTACT CHANNEL AND COMPLAINTS RECORD
Coaktion centralises all requests, petitions and complaints relating to the Processing of Personal Data with the Data Protection Officer (DPO).
- Data Subjects wishing to exercise their rights (as described in section 8 of this Policy) or to report incidents must send their request exclusively to the official e-mail address: dpo@coaktion.com.
- Requests will be received, reviewed and answered clearly and completely within 15 (fifteen) days, or as otherwise required by the Applicable Data Protection Laws of each jurisdiction.
15. INVESTIGATION AND NOTIFICATION OF SECURITY INCIDENTS
Coaktion maintains rigorous information security processes. Nevertheless, in the event of any suspected or confirmed security incident involving personal data (such as leakage, destruction, loss, alteration or unauthorised access), the following guidelines must be strictly observed:
- Internal Notification: every employee, service provider or partner must immediately notify the DPO (dpo@coaktion.com) and the Corporate Technology function upon becoming aware of an adverse event.
- Coaktion as Processor: where the incident affects data processed on behalf of our Clients (Controllers), Coaktion will notify them formally and without undue delay, providing all technical support necessary for the investigation and mitigation of the risks.
- Coaktion as Controller: where the incident affects data under Coaktion’s control and may give rise to relevant risk or harm to data subjects, Coaktion will make the official notification to the Supervisory Authorities and to the data subjects concerned within the period established by the legislation in force in each jurisdiction (e.g. 72 hours under the GDPR or 3 business days under the ANPD).
16. MUTUAL ASSISTANCE AND COOPERATION WITH SUPERVISORY AUTHORITIES
Coaktion will act collaboratively with the Supervisory Authorities and other competent authorities on matters relating to data privacy. We undertake to respond to requests for information, adopt good practices and facilitate inspections, always within legal limits and safeguarding our trade and industrial secrets. The DPO is the exclusive point of contact for this communication.
17. REVIEWS AND UPDATES
This Privacy and Data Protection Policy takes effect from the date of its approval and publication, remains in force for an indefinite period and revokes any provisions to the contrary. To ensure its continued adequacy in the face of technological change, operational needs or new resolutions from the Supervisory Authorities, this document will be critically reviewed and updated at least annually, or whenever necessary, by the Privacy function with the support of the DPO and Senior Management.
ANNEX I
Details of the Coaktion group companies:
AKTIE PARTICIPAÇÕES LTDA. (Coaktion), a limited liability company headquartered at Rua Manoel Coelho, no. 676, room 710, Centro, city of São Caetano do Sul, State of São Paulo, Brazil, postcode 09510-101, enrolled with the CNPJ/ME under no. 33.108.579/0001-60, with its constitutional documents duly filed with JUCESP under NIRE 35231427106 (“Coaktion”).
AKTIE NOW SERVIÇOS TECNOLÓGICOS E EMPRESARIAIS LTDA., a limited liability company headquartered at Rua Manoel Coelho, no. 676, room 710, Centro, city of São Caetano do Sul, State of São Paulo, Brazil, postcode 09510-101, enrolled with the National Register of Legal Entities of the Ministry of Economy (“CNPJ/ME”) under no. 24.552.976/0001-35, with its constitutional documents duly filed with the São Paulo State Board of Trade (“JUCESP”) under Company Registration Identification Number (“NIRE”) 3522978790 (“AKTIE NOW”).
DROZ TECNOLOGIA DA INFORMAÇÃO LTDA., a limited liability company headquartered at Rua Manoel Coelho, no. 676, room 710, Centro, city of São Caetano do Sul, State of São Paulo, Brazil, postcode 09510-101, enrolled with the CNPJ/ME under no. 30.488.257/0001-03, with its constitutional documents duly filed with JUCESP under NIRE 35230962628 (“DROZ”).
MYPBX SERVIÇOS E TECNOLOGIA LTDA., a limited liability company headquartered at Rua Manoel Coelho, no. 676, room 710, Centro, city of São Caetano do Sul, State of São Paulo, Brazil, postcode 09510-101, enrolled with the CNPJ/ME under no. 10.717.581/0001-30, with its constitutional documents duly filed with JUCESP under NIRE 35223070113 (“MYPBX”).
SYNTRIKA SERVICOS TECNOLOGICOS E EMPRESARIAIS LTDA., a limited liability company headquartered at Rua Manoel Coelho, no. 676, room 710, Centro, city of São Caetano do Sul, State of São Paulo, Brazil, postcode 09510-101, enrolled with the CNPJ/ME under no. 62.029.390/0001-80, with its constitutional documents duly filed with JUCESP under NIRE no. 35267576713 (“Syntrika”).
CO.AKTION LLC, a limited liability company headquartered at 2 S. Biscayne Boulevard, Suite 2450, Miami, FL 33131, United States of America, holding Employer Identification Number (EIN) no. 87-1734016.