Privacy and Personal Data Protection Policy
Last updated: May 13, 2026
INTRODUCTION
We appreciate your trust in sharing your personal data with us and recognize that you may want to know how we handle this information. Sitawi Finanças do Bem has created this Policy to help you understand how we process personal data and its main references are the Constitution of the Republic, especially article 5, items X and LXXIX, and Law No. 13.709/2018 (General Law on the Protection of Personal Data – LGPD), as well as, where applicable, rules, regulations and guidelines issued by the National Data Protection Authority (ANPD).
This Policy serves to provide complete transparency regarding how we handle your Personal Data. You can access and view this Policy at any time through the Website.
TARGET AUDIENCE
This Privacy and Personal Data Protection Policy (“Policy”) is intended for the following individuals:
- To all suppliers, partners, contractors and investors who in some way establish a relationship with Sitawi;
- All those who interact: 1) with our portal (http://www.sitawi.net) (“Website”), owned and managed by Sitawi; 2) with our social networks; 3) with our messaging applications; 4) with our Crowdfunding for Impact platform; 5) with other communication channels not expressly provided for.
CONTROLLER DATA
Sitawi Finanças do Bem
CNPJ: 09.607.915/0001-34
Address: Teodoro Sampaio, 1629 / 1633 – Pinheiros Neighborhood – Zip Code: 05.405-150 São Paulo, SP.
DEFINITIONS
the) Personal data:Information related to a natural person capable of directly or indirectly identifying them, such as name, surname, document numbers, personal records, login, address, telephone, postal code (CEP), Work Card number (CTPS), location data, information used in financial profile.
b) Sensitive personal data:Any personal data relating to racial or ethnic origin, religious belief, political or philosophical opinion, trade union membership, religion, health data, sexual life, genetic or biometric data.
w) Holder:Natural person to whom the personal data that are the object of the processing refer.
d) Controller:Natural or legal person, under public or private law, responsible for decisions regarding the processing of personal data.
and) Operator:Person who carries out the processing of personal data on behalf of the controller.
f) In charge:Person appointed within the Organization who acts as a communication channel between the controller, data subjects and the National Data Protection Authority (ANPD).
g) Data processing:Any operation performed with personal data, such as collection, production, reception, processing, archiving, storage, consultation, use, sharing, communication, transfer, deletion, and other operations foreseen in the LGPD (Brazilian General Data Protection Law).
h) Anonymization:Process through which data loses the possibility of association, directly or indirectly, with an individual, through available technical means.
i) Privacy NoticeA specific document, usually aimed at a particular audience or processing context, that objectively presents how and why personal data is processed.
j) Terms of UseRules applicable to accessing and using a website, platform, system, or digital service, including browsing conditions, responsibilities, usage limitations, and other user obligations.
DATA PROCESSING
When processing third-party personal data, Sitawi complies with the provisions of the LGPD (Brazilian General Data Protection Law), respects the rights of data subjects, and adopts measures to preserve the fundamental rights of freedom, privacy, and the free development of the personality of the natural person.
Therefore, it is essential that Sitawi expressly discriminates the hypotheses in which it carries out data processing. These are:
the) Consent:When the data subject expresses his/her authorization in a free, informed and unequivocal manner for the processing of his/her personal data.
b) Contract Execution:When processing is necessary for the performance of a contract or preliminary procedures relating to a contract to which the data subject is a party.
w) Compliance with Legal or Regulatory Obligation:When processing is necessary for compliance with a legal or regulatory obligation to which the controller is subject.
d) Protection of Life or Physical Integrity: When the processing is essential to protect the life or physical integrity of the holder or third parties.
and) Legitimate Interest:When the processing meets the legitimate interests of the controller or third parties, provided that the fundamental rights and freedoms of the data subject prevail.
f) Regular exercise of rights: When necessary to defend the rights of Sitawi, the holders, or third parties, including in judicial, administrative, or arbitration proceedings.
Other legal hypotheses foreseen in the LGPD (Brazilian General Data Protection Law) may be used when compatible with the stated purpose and duly documented.
Regardless of the legal basis used for data processing, Sitawi will strive to inform the data subject, clearly and appropriately to the context, of the applicable legal basis, ensuring transparency and access to information. If you have any questions, we are available to provide clarification.
DATA COLLECTED
Sitawi may collect your data through forms, signed contracts, service provision, use of and interaction with products, businesses, experiences and institutional channels, both online and offline, as well as automatically, through cookies or similar technologies related to the platforms used.
We list below the hypotheses in which we collect your data, as well as what information is collected. Sitawi informs that the table below is illustrative, and it is possible that other data collection hypotheses may be used.
Provided by you through the Contact Us system on our website.
|
|
Provided by you when filling out forms on our Registration Pages
|
|
Provided by you when participating in our institutional events or those in which we participate |
|
Provided by you when you opt-in to our newsletter or marketing campaigns |
|
Provided by you when communicating with us via WhatsApp |
|
Provided by you through the Benfeitoria platform |
|
Provided by you on the Crowdlending for Impact platform |
|
Collected automatically when you interact with us on our social media channels |
|
Information arising from the normal use of our Website |
For such collection, we may make use of some standard technologies, such as cookies, pixel tags, beacons and local shared objects, which are used for the purpose of improving your browsing experience on the Website, according to your habits and preferences. |
Data shared through the execution of legal instruments such as contracts, terms or memoranda (e.g. partnership, collaboration, cooperation, agreement, donation, provision of services…) |
|
USE OF DATA
Personal data may be used for the following purposes:
- Communication: The information collected by the Contact system of our Website and those collected during your interaction with us through social networks or whatsapp will be used to respond to demands, complaints or suggestions presented by you. Depending on the severity of the complaint, we may send the collected data to the legal department to better address your demands.
- Content targeting and participation in marketing campaigns: We may use the data collected from participants in our newsletter, our events and visitors to our Website to improve the content available on our social networks, as well as to conduct campaigns and send marketing messages through any means of communication, such as, but not limited to, emails and messaging applications.
- To apply for the position offered in our team of employees
- To carry out investigations and preventive measures, detecting conduct and activities that are in disagreement with our Code of Ethics and Conduct or that are prohibited or illegal.
- Data collected to comply with legal obligations: We are required by law to keep some basic data to log access to our Website, such as the IP address of the originating connection, with date and time. Such data are kept for the legally prescribed minimum period of 6 (six) months. Occasionally, other data may also be stored to comply with legal obligations, such as those related to participation in our Programs.
- Data collected for the execution of activities provided for in a Legal Instrument: In order to achieve our corporate objectives, we enter into various legal instruments with third parties, such as Contracts, Partnerships, Memorandums, among others, which may eventually require the use of personal data to carry out the activities set out in the Instrument.
- Secondary purposes: We may also use the collected data for secondary purposes that are not incompatible with or excessive in relation to the purposes listed above, including for defense purposes in judicial, administrative or extrajudicial disputes, always in accordance with Brazilian law and in observance of your individual rights and freedoms.
PROCESSING OF PERSONAL DATA OF CHILDREN, ADOLESCENTS AND INCAPACITATED PERSONS
Sitawi may process personal data of children, adolescents, or incapacitated persons when necessary for the execution of projects, programs, scholarships, courses, training activities, accountability, legal or regulatory obligations, regular exercise of rights, or other purposes compatible with its institutional activities.
In these situations, the processing must observe the best interests of the child and adolescent, the specific purpose informed, the minimization of data collected, the adoption of security measures compatible with the sensitivity of the information and, when applicable, the obtaining of specific and prominent consent from at least one of the parents or legal guardian.
Sitawi may request identification data, contact information, documentation, information about legal guardians, academic information, bank details, or other information strictly necessary to enable participation in the project, payment of scholarships, monitoring of activities, compliance with requirements of the donor, partner, educational institution, or competent authority, always observing the applicable legal bases.
The sharing of this data with partners, donors, educational institutions, service providers, public bodies, or third parties involved in the project will only occur when necessary, proportionate, and linked to the stated purpose, subject to access controls, confidentiality, and other applicable protection measures.
USE OF TECHNOLOGIES, AUTOMATION AND ARTIFICIAL INTELLIGENCE
Sitawi may use technological tools, automation resources, and artificial intelligence solutions to support institutional, administrative, operational, communication, analysis, project management, process improvement, and information security activities, always in accordance with this Policy, the LGPD (Brazilian General Data Protection Law), and applicable internal policies.
If the processing of personal data through these tools becomes necessary, Sitawi will seek to limit its use to the information strictly necessary for the intended purpose, assess privacy and security risks, apply access controls, avoid the insertion of excessive or unnecessary data and, when applicable, adopt anonymization, pseudonymization or other protection measures.
The use of technologies and artificial intelligence does not relieve Sitawi of its responsibility to observe the rights of data subjects, to be transparent about the purposes of data processing, and to adopt measures proportionate to the risk, without prejudice to the specific guidelines set forth in the Information Security Policy and other applicable internal regulations.
DATA SHARING
Sitawi may, in order to fulfill its institutional purpose, share personal data and/or sensitive personal data with public bodies, regulators, third-party companies and partners, in the following cases:
- Partner companies, when necessary or relevant for the execution of our services, including, but not limited to, technical support for maintaining the availability of the Website and systems used by the organization, including in crowdfunding projects and requests received through the Contact Us system;
- To protect our interests in any conflict or litigation, even if judicial, administrative or arbitration;
- In the event of changes or corporate transactions involving us, if the sharing of data proves necessary for the regular continuity of the Website services and those related to our Programs;
- With administrative and/or judicial authorities, upon judicial determination to that effect or request from authorities that have legal competence to do so.
The sharing of such data must be preceded by a contractual adjustment, agreement or instrument that regulates the purpose and responsibilities of the parties.
The parties must implement access control management for personal data and/or sensitive personal data that they process, and must collect confidentiality and non-disclosure commitments from their employees.
COOKIES
are small files that collect personal data as you browse the internet. Cookies serve various purposes such as:
- Allow the Website to load correctly and allow you to navigate and make use of all available features normally;
- Allow the Website to remember Users’ choices, to provide a more personalized experience.
- They can be used to provide more relevant and interesting content to users, to present or limit targeted advertising on the Website, as well as to compile information about the use of the Website to help improve its structure and content. For these purposes, tools such as RD Station, Google Analytics or similar technologies may be used, according to the applicable settings.
When you access our Website for the first time through a device, you may be asked for permission to use non-essential cookies, where applicable. After this registration, we may store cookies on your device to remember you for your next session.
To disable, refuse, or delete cookies, please follow the instructions provided by your browser or platform. The links are available below:
Finally, we remind you that if you disable some cookies, certain services may not function optimally.
RETENTION OF PERSONAL DATA
Your Personal Data will be retained for the time necessary to satisfy the purpose for which the data was collected or upon your request, as explored in this Policy.
In cases where data was collected for sending newsletters and marketing campaigns, we will keep your data as long as there is engagement on your part. In practice, this means that after 180 days (6 months) without any type of engagement and direct or indirect interaction with our content, we delete any information that could identify you.
Furthermore, data may be stored for a specific period, depending on the specific case, as detailed below:
- binding to legal, regulatory or contractual obligations related to your interaction with us;
- need to conduct any eventual contractual negotiations;
- need to comply with any legal or regulatory obligation; or
- The existence of another legitimate and documented basis for retention.
When the Personal Data we collect is no longer needed, it will be securely deleted or anonymized so that it cannot be associated with or traced back to you.
INFORMATION SECURITY MEASURES
All information collected is treated as confidential, ensuring that it will be stored in accordance with the provisions of this Policy and with the adoption of appropriate technical and administrative security measures, according to the degree of sensitivity of the data and the risks inherent to the activity.
Among the security measures we adopt are the use of data encryption, information access control, the use of firewalls and the implementation of an internal information security policy, architecture of the software solution with intrusion prevention, use of HTTPS.
However, despite our best efforts, it is impossible to guarantee that malicious actors will not be able to access or misuse this data. For this reason, we encourage data subjects and processors to take appropriate technical security measures, such as browsing on secure networks.
RIGHTS OF THE HOLDERS
The owner of personal data processed within the scope of Sitawi's activities has the following rights:
- Confirmation: The right to question whether any of your personal data is being processed by Sitawi
- Access: request access to your stored personal data, by making a request through our contact channel dpo@sitawi.net (mailto:dpo@sitawi.net)
- Correction: In case of incorrect data, the holder may request the correction or update of their data, by making a request through our contact channel dpo@sitawi.net (mailto:dpo@sitawi.net)
- Exclusion: At any time, you can request the deletion of your personal data through our contact channel dpo@sitawi.net (mailto:dpo@sitawi.net). In this case, it is possible that after the request for deletion of your data, some data may remain stored, for the purpose of complying with legal obligations or for the protection of the legal interests of Sitawi or its business partners.
- Unsubscribe: Sitawi maintains an easy opt-out option applicable to situations in which this is requested.
- Portability: You may require portability of data stored on our systems. This means that, in case of this type of request, SITAWI will deliver a copy of your personal data in a common and interoperable reading format, however, compatibility between such format and the technical configurations of the company receiving this data cannot be guaranteed.
- Opposition: If you understand that your personal data is being processed in violation of the law, you may object to such processing by making a request through our contact channel dpo@sitawi.net (mailto:dpo@sitawi.net).
- Anonymization, blocking, or deletion: The data subject may request, in legally applicable cases, the anonymization, blocking, or deletion of unnecessary, excessive, or unlawfully processed personal data.
- Information regarding the sharing and revocation of consent: The data subject may request information about the public or private entities with which Sitawi has shared personal data and, when the processing is based on consent, may request its revocation, subject to the applicable consequences.
All requests presented above will be treated free of charge, and will be subject to a prior assessment of their identity and the feasibility of the service, in order to comply with any legal obligations that prevent the complete fulfillment of the requests of the right holders.
PROCEDURE FOR MANAGING INCIDENTS INVOLVING PERSONAL DATA AND SENSITIVE PERSONAL DATA
It is the duty of every Sitawi employee, upon becoming aware of or suspecting any threat, vulnerability, or incident that may involve personal data or sensitive personal data, to immediately notify the responsible area via the email address dpo@sitawi.net for analysis, registration, and adoption of appropriate containment measures.
The area responsible for the indicated channel must register the event, assess its origin, confirm whether there was a security incident involving personal data, identify the nature and category of the data affected, the systems or documents involved, the estimated number of data subjects, the data subjects potentially affected, the existence of sensitive data, data of children, adolescents or vulnerable persons, financial data, authentication data, data protected by confidentiality or large-scale processing, as well as the possible impacts on the data subjects.
The classification of the incident should consider, at a minimum, the context of the processing, the nature, quantity and sensitivity of the data involved, the extent of the event, the technical and administrative measures already in place, the potential material, moral or reputational damage to the data subjects, and the adequacy of the containment and mitigation measures adopted.
Incidents must be documented in an internal report or incident log, even if, after analysis, they are not classified as requiring communication to the ANPD (National Data Protection Authority) or data subjects. This log must contain a description of the event, date and time of knowledge and, when possible, of occurrence, measures taken, responsible parties involved, conclusion of the analysis, justification for the classification and supporting evidence, and must be kept for a minimum period of 5 (five) years.
When an incident is confirmed and could cause significant risk or harm to data subjects, Sitawi must assess the need to notify the ANPD (National Data Protection Authority) and the data subjects, observing the applicable deadlines and requirements. As a rule, notification to the ANPD must occur within 3 (three) business days of confirmation of the incident, unless a different deadline is provided for in specific legislation.
The communication to the ANPD (National Data Protection Authority) must contain, whenever available, the information required by applicable regulations, including a description of the incident, date and time of knowledge and occurrence, categories and estimated number of data subjects affected, nature and category of personal data involved, possible consequences, existing technical and administrative security measures, measures adopted to contain or mitigate the effects of the incident, and justification for any inability to provide complete information at the time of communication.
Communication to data subjects, when necessary, should be carried out in clear and accessible language, preferably in a direct and individualized manner, containing sufficient information for them to understand what happened and adopt protective measures. If the information is not fully available within the applicable timeframe, the communication may be supplemented later, with justification.
After the incident has been contained and closed, the responsible area should assess the causes, record lessons learned, and propose improvements in controls, processes, contracts, training, information security, and data governance, considering both digital and non-digital means.
INTERNATIONAL TRANSFER OF PERSONAL DATA
Sitawi will generally not transfer personal data it processes internationally, except in cases permitted by law, such as, but not limited to, when it involves countries or international organizations that offer a level of personal data protection equal to or higher than that provided for in Brazilian legislation, and when it is possible to guarantee compliance with the principles, the rights of the data subject, and the data protection regime provided for in the Law through specific contractual clauses and other valid mechanisms provided for in applicable legislation and regulations.
COMMUNICATION CHANNEL
Transparency regarding the processing of your personal data is a priority for Sitawi. In addition to the information provided in this Privacy and Personal Data Protection Policy, you may also exercise your rights at any time by sending requests to the email address: dpo@sitawi.net (mailto:dpo@sitawi.net), which will be responded to within the legal deadline.
LEGISLATION AND JURISDICTION
This Policy will be governed, interpreted and executed in accordance with the Laws of the Federative Republic of Brazil, especially Law No. 13,709/2018, regardless of the Laws of other states or Countries, with the jurisdiction of the city of São Paulo, State of São Paulo, being competent to resolve any doubts arising from this document.
POLICY UPDATE
Sitawi may update this Privacy and Personal Data Protection Policy periodically, and the version in force will always be the most recent, always respecting the principles set forth in the General Personal Data Protection Law. To check the date of the version in force, check the “Update date” at the beginning of this document.