1. Introduction
GOUV SERVIÇOS DE IMIGRAÇÃO E COMÉRCIO EXTERIOR LTDA (hereinafter referred to as “CONSULARIS” or “we”) values and protects the privacy of all its clients and users. In compliance with the Brazilian General Data Protection Law (Lei nº 13.709/2018 – LGPD) and the General Data Protection Regulation (GDPR) of the European Union, we have established this Data Protection and Electronic Signature Policy to ensure that the collection, use, and processing of personal data are carried out in a transparent, ethical manner and in full compliance with all legal requirements.
2. Purpose of the Data Protection Policy
This policy aims to ensure compliance with applicable data protection legislation (LGPD and GDPR), safeguarding the rights of data subjects in all CONSULARIS operations, especially within Latin America, Mercosur, and the European Union.
3. Definitions
- Personal Data: Any information relating to an identified or identifiable natural person.
- Sensitive Data: Data that reveals racial or ethnic origin, religious belief, political opinion, trade union membership, or data concerning health or sexual life, among others.
- Controller: The entity that determines the purposes and means of processing personal data.
- Processor: The entity that processes personal data on behalf of the controller.
- Consent: A free, informed, and unequivocal authorization given by the data subject for the processing of their data.
- Data Protection Officer (DPO): The person designated by CONSULARIS to act as the contact point for data protection matters.
4. Principles of Data Processing
CONSULARIS is committed to processing personal data in accordance with the following principles:
- Lawfulness, Fairness, and Transparency: Personal data will be processed in a lawful, fair, and transparent manner.
- Purpose Limitation: Personal data collected will have specific, explicit, and legitimate purposes.
- Data Minimization: We will collect only the personal data necessary to perform our services.
- Accuracy: Personal data must be accurate and, where necessary, kept up to date.
- Storage Limitation: Data will be stored only for the period necessary to fulfill its purposes.
- Integrity and Confidentiality: Appropriate measures will be implemented to protect data against unauthorized or unlawful processing.
5. Types of Data Collected
CONSULARIS may collect the following types of personal data, depending on the service provided:
- Identification Data: Full name, CPF/CNPJ, passport number, address, date of birth.
- Contact Data: Email address, phone number, residential address.
- Sensitive Data: Nationality, marital status, health information, and biometric data, when strictly necessary for immigration and citizenship processes.
- Financial Data: Banking and payment information for the execution of contracts.
- Browsing Data: IP address, browser type, length of visit, and browsing behavior on our websites.
6. Legal Basis for Data Processing
The processing of personal data by CONSULARIS is carried out based on the following legal grounds:
- Data Subject’s Consent: For activities involving the processing of sensitive data or when explicit consent from the data subject is required.
- Contract Performance: When processing is necessary for the performance of a contract with the data subject or for the execution of pre-contractual measures.
- Compliance with Legal or Regulatory Obligations: To meet legal and regulatory requirements applicable to CONSULARIS.
- Legitimate Interest: To protect CONSULARIS’ legitimate interests, always respecting the rights and freedoms of the data subject.
- Execution of Public Policies: In cases involving the provision of diplomatic or governmental services.
7. Data Sharing and International Transfer of Data
CONSULARIS shares personal data with third parties only when necessary for the execution of our services. Data sharing may occur with:
- Service Providers: Law firms, notaries, and other partners required to perform the contracted services.
- Government Authorities: To comply with legal and regulatory requirements in immigration and citizenship processes.
- International Entities: For diplomatic and immigration services, in accordance with data protection laws.
International data transfers will be carried out only to countries that provide an adequate level of data protection in accordance with the GDPR or the LGPD. For countries outside these jurisdictions, additional safeguards will be implemented, such as standard contractual clauses approved by the competent authorities.
8. Data Retention
Personal data will be retained for as long as necessary to fulfill the purposes for which they were collected. After the processing period ends, the data may be anonymized or deleted, except when retention is required to comply with legal or regulatory obligations.
9. Data Subject Rights
In accordance with the LGPD and the GDPR, data subjects have the following rights:
- Confirmation of Processing: The right to confirm whether their personal data is being processed.
- Access: The right to obtain access to their personal data.
- Correction: The right to request the correction of inaccurate or outdated data.
- Anonymization, Blocking, or Deletion: The right to request the anonymization, blocking, or deletion of unnecessary or excessive data.
- Data Portability: The right to receive their data in a structured format.
- Withdrawal of Consent: The right to withdraw consent at any time.
- Objection: The right to object to data processing when legal bases are not complied with.
- Deletion of Data: The right to request the deletion of personal data, provided there is no legal justification for its retention.
To exercise these rights, the data subject may contact CONSULARIS’ Data Protection Officer through the channels indicated at the end of this policy.
10. Electronic Signature Policy
CONSULARIS uses electronic signatures in compliance with Provisional Measure No. 2.200-2/2001 in Brazil, which established the Brazilian Public Key Infrastructure (ICP-Brasil), and with the eIDAS Regulation (Regulation (EU) No. 910/2014) in the European Union, which governs electronic identification and trust services.
Electronic signatures have the same legal validity as handwritten signatures and are applicable in the following contexts:
- Electronic Contracts: Contractual documents and agreements entered into between CONSULARIS and its clients or suppliers.
- Document Authentication: Verification of the authenticity of documents sent to or received by CONSULARIS.
- Immigration and Citizenship Processes: Use of electronic signatures to simplify and authenticate documents in administrative and governmental procedures.
Electronic signatures are protected by encryption and follow the security protocols established by ICP-Brasil and eIDAS standards, ensuring their integrity, authenticity, and confidentiality.
11. Security Measures
CONSULARIS adopts technical and organizational measures to protect personal data against unauthorized access, destruction, loss, alteration, or improper disclosure. Key measures include:
- Data Encryption: All stored and transmitted data are encrypted to ensure their security.
- Access Control: Only authorized individuals have access to personal data, based on necessity and confidentiality criteria.
- Continuous Monitoring: Security systems are continuously monitored to detect and prevent incidents.
- Staff Training: Our team receives regular training in compliance with data protection standards.
12. Changes to This Policy
CONSULARIS reserves the right to update this Data Protection and Electronic Signature Policy periodically to ensure compliance with changes in applicable legislation or in our internal processes. We recommend that data subjects review this policy regularly to stay informed about any updates.
13. Data Protection Officer Contact Information
For questions, requests, or further information regarding the processing of personal data, please contact our Data Protection Officer:
- Email:info@consularis.ro
- Phone: +55 81 98607 4163
This policy is in compliance with the LGPD (Law No. 13.709/2018) and the GDPR (Regulation (EU) 2016/679).