Privacy Policy
How RainbowTec processes personal data as a Data Processor under the Brazilian LGPD and the ISO/IEC 27001 and ISO/IEC 27701 standards.
POL-SGSI&PI-001 · Rainbow Tecnologia e Consultoria Ltda
1. Purpose
This Privacy Policy aims to establish clear, transparent, and accessible guidelines on the processing of personal data carried out by Rainbow Tecnologia e Consultoria Ltda., in accordance with the Brazilian General Data Protection Law (LGPD – Law No. 13.709/2018), as well as the information security and privacy best practices defined by ISO/IEC 27001 and ISO/IEC 27701 standards.
The organization acts as a Data Processor, carrying out the processing of personal data exclusively on behalf of and according to the documented instructions of the Data Controllers, adopting adequate technical and administrative measures to ensure the security, confidentiality, integrity, and availability of the information processed.
2. Scope
This Policy applies to:
- Visitors of the institutional website
- Clients, partners, suppliers, and employees whose personal data is processed by the organization
Processing activities performed in the context of contract execution, service delivery, technical support, and compliance with legal or regulatory obligations.
This Policy does not apply to personal data processing activities carried out directly by Data Controllers, who are responsible for defining the purposes and legal bases applicable to such processing.
3. Terms and Definitions
Personal Data: information related to an identified or identifiable natural person.
Sensitive Personal Data: genetic or biometric data.
Data Subject: the natural person to whom the personal data refers.
Controller: the natural or legal person responsible for decisions regarding the processing of personal data.
Processor: the natural or legal person who processes personal data on behalf of the Controller.
Processing: any operation performed with personal data, such as collection, use, access, storage, sharing, or deletion.
ANPD: the Brazilian National Data Protection Authority, responsible for overseeing personal data protection in Brazil.
4. Methodology
4.1 Acting as a Data Processor
- Processing is carried out strictly according to the Controller’s documented instructions
- The organization does not define its own purposes for the use of personal data
- Personal data is not used for purposes other than those contractually established.
4.2 Information Security and Privacy
The organization adopts technical and administrative measures aligned with ISO/IEC 27001 and ISO/IEC 27701 standards, including, when applicable:
- Logical and physical access control
- Segregation of duties
- Protection against unauthorized access
- Access monitoring and logging
- Incident management procedures
- Information security and privacy awareness and training.
4.3 Data Sharing
Personal data may be shared only when necessary for the execution of contracted activities, always following the Controller’s instructions and complying with security and confidentiality requirements.
4.4 Data Subject Rights
Requests related to data subject rights must be addressed to the Data Controller. The organization, as Processor, will provide technical and operational support as applicable.
4.5 Security Incidents
In the event of a security incident involving personal data, the organization will follow its internal procedures and notify the Controller, in accordance with the LGPD and the contractual agreements in place.
5. Records and Evidence
For legal, contractual, and regulatory compliance purposes, the organization maintains, when applicable:
- Records of processing activities performed as a Processor
- Evidence of information security controls
- System and information access logs
- Documented incident response procedures
- Contracts and data processing agreements with Controllers
- Training and awareness program records.
Records are kept for the period necessary to meet legal, regulatory, and contractual obligations, observing the principles of necessity and data minimization.
6. Contact
For questions related to this Privacy Policy or to personal data protection, please contact:
Company: Rainbow Tecnologia e Consultoria Ltda
Email: contact@rainbowtec.com
Phone: +55 11 2344-0350
By using this website, you acknowledge and agree to the terms of this Privacy Policy.
